Introduction
Threat Group-1314 is an unattributed threat group that has used compromised credentials to log into a victimβs remote access infrastructure. Dell TG-1314
Activities and Tactics
Information pending cataloguing.
Notable Campaigns
Information pending cataloguing.
Tactics, Techniques, and Procedures (TTPs)
- T1021.002 SMB/Windows Admin Shares
- T1059.003 Windows Command Shell
- T1072 Software Deployment Tools
- T1078.002 Domain Accounts
ATT&CK technique IDs (denormalized)
Notable Indicators of Compromise (IOCs)
No curated IOCs are currently published for this actor. This section will be updated when stable, attributable indicators are available.
Malware and Tools
- RemoteCMD:
- CyberGate:
- Cyber Eye RAT:
- Remote Utilities:
- RemotePC:
MITRE ATT&CK Software
Attribution and Evidence
Information pending cataloguing.
References
[1] mitre-attack [4] Dell TG-1314 Dell SecureWorks Counter Threat Unit Special Operations Team. (2015, May 28). Living off the Land. Retrieved January 26, 2016.