Skip to content

Commit

Permalink
Todoooloooo!
Browse files Browse the repository at this point in the history
  • Loading branch information
blueteamer committed Mar 13, 2024
1 parent 7cfd481 commit c62c3e5
Showing 1 changed file with 1 addition and 1 deletion.
Original file line number Diff line number Diff line change
Expand Up @@ -49,7 +49,7 @@ The threat group was observed in quickly reacting to defenders actions in terms

Mapping their operations onto the MITRE ATT&CK framework reveals a comprehensive attack chain:

- Reconnaissance: Octo Tempest demonstrates an intimate knowledge of targeted organizations, IR adn administration processes, leveraging illicit data brokers[^fn1] [^fn2] and previous breaches for intelligence gathering.
- Reconnaissance: Octo Tempest demonstrates an intimate knowledge of targeted organizations, IR adn administration processes, leveraging illicit data brokers and previous breaches[^fn1] [^fn2] for intelligence gathering.
- Initial Access: They employ smishing and helpdesk social engineering to gain initial entry, often bypassing multi-factor authentication (MFA) through convincing tactics.
- Persistence: The group maintains access through a plethora of remote monitoring and management tools, ensuring a backdoor into the environment.
- Defense Evasion: Octo Tempest adeptly evades security controls, disabling antivirus, and firewalls, and using anonymizing services to obscure their activities.
Expand Down

0 comments on commit c62c3e5

Please sign in to comment.