Meta tags:
Headings (most frequently used words):
stage, capabilities, drive, by, target, procedure, examples, mitigations, detection, strategy, references, other, sub, techniques, of,
Text of the page (most frequently used words):
and (21), the (19), retrieved (16), drive (13), may (11), websites (11), compromise (11), att (10), all (10), web (10), malicious (9), has (9), t1608 (9), enterprise (8), 2024 (8), content (8), target (8), compromised (8), detection (7), 2021 (7), march (7), 2022 (7), infrastructure (7), adversary (7), stage (7), threat (6), october (6), for (6), such (6), adversaries (6), user (6), website (5), ics (5), mobile (5), none (5), domains (5), techniques (5), transparent (5), tribe (5), november (5), with (5), watering (5), this (5), mitre (4), defenses (4), sub (4), malware (4), 2016 (4), fin7 (4), august (4), through (4), hole (4), other (4), exploitation (4), infect (4), into (4), exploit (4), browser (4), controlled (4), legitimate (4), that (4), version (4), capabilities (4), are (3), use (3), resources (3), software (3), cti (3), data (3), mitigations (3), its (3), september (3), actor (3), socgholish (3), from (3), fake (3), luminousmoth (3), 2020 (3), used (3), group (3), strategic (3), description (3), name (3), technique (3), set (3), targeted (3), victims (3), victim (3), javascript (3), digital (3), c0010 (3), 004 (3), upload (3), 2015 (2), 2026 (2), corporation (2), reference (2), campaigns (2), groups (2), components (2), analytics (2), strategies (2), assets (2), tactics (2), matrices (2), core (2), objects (2), expands (2), link (2), found (2), operation (2), red (2), canary (2), staging (2), very (2), update (2), april (2), activity (2), targeting (2), december (2), scripts (2), israeli (2), shipping (2), government (2), attack (2), details (2), deliver (2), been (2), previously (2), internet (2), staged (2), outside (2), behavior (2), analytic (2), controls (2), based (2), pre (2), tools (2), potential (2), then (2), interest (2), 3390 (2), via (2), download (2), mustard (2), tempest (2), modified (2), host (2), dragonfly (2), curium (2), information (2), them (2), but (2), pages (2), profile (2), apt32 (2), specific (2), users (2), also (2), prior (2), systems (2), browsing (2), site (2), can (2), ckcon (2), person (2), tickets (2), faq (2), registered, trademarks, cookie, preferences, changelog, privacy, policy, terms, contact, reset, filters, malhotra, apt, windows, arsenal, falcone, conant, projectm, between, pakistani, huss, june, secureworks, gold, prelude, report, milenkoski, diversifies, counter, defenders, andrew, northern, real, february, botezatu, etl, july, plugx, file, exfiltration, persistence, revisited, abdo, power, hour, archaeology, evolution, slowik, baffling, berserk, bear, decade, critical, pwc, intelligence, 2023, yellow, liderc, ships, delivers, imaploader, mandiant, israel, research, team, suspected, iranian, healthcare, energy, sectors, adair, lancaster, oceanlotus, extending, cyber, espionage, operations, blasco, 2014, scanbox, reconnaissance, framework, attacks, gallagher, newly, discovered, chinese, hacking, hacked, 100, holes, january, kindlund, 2012, cfr, references, patterns, utilized, have, identified, scanning, uncover, when, much, will, take, place, visibility, organization, making, difficult, efforts, focused, phases, lifecycle, client, execution, an1957, det0825, strategy, cannot, easily, mitigated, preventive, since, behaviors, performed, scope, m1056, mitigation, hyperlinks, iframes, njrat, crimson, g0134, embedded, code, screen, address, their, they, g0027, injected, g1020, redirected, machines, webpage, html, injection, g1014, product, multiple, links, point, trojanized, versions, offered, products, g0046, redirect, traffic, kits, g0035, fingerprint, g1012, actors, login, page, company, likely, established, collected, visitor, stood, containing, numerous, articles, scraped, make, appear, some, these, include, g0050, procedure, examples, live, permalink, 2025, last, created, platforms, resource, development, tactic, purchase, similar, homoglyphs, typosquatting, different, top, level, domain, etc, during, acquisition, help, facilitate, ones, visited, community, particular, industry, region, where, goal, shared, kind, campaign, referred, addition, scripting, ensure, vulnerable, attempting, gather, crafting, advertisements, purchasing, space, providers, malvertising, modifying, script, files, served, publicly, writeable, cloud, storage, buckets, inserting, controllable, forum, posts, inject, done, number, ways, including, prepare, operational, environment, visit, over, normal, course, endpoint, sites, cases, typically, often, not, requiring, any, extra, interaction, once, landing, non, must, needed, who, browse, acquired, acquire, application, access, token, seo, poisoning, 006, 005, install, certificate, 003, tool, 002, 001, home, open, join, mclean, hotel, location, register, here, search, blog, contribute, benefactors, legal, branding, updates, history, engage, advisory, council, learn, more, about, get, started, detections,
Text of the page (random words):
stage capabilities drive by target sub technique t1608 004 enterprise mitre att ck matrices enterprise mobile ics tactics enterprise mobile ics techniques enterprise mobile ics defenses mitigations enterprise mobile ics assets detections detection strategies analytics data components cti groups software campaigns resources get started learn more about att ck att ck advisory council att ckcon att ck data tools faq engage with att ck version history updates legal branding benefactors contribute blog search att ckcon 7 0 in person tickets are open join us october 27 28 2026 in mclean va register here for in person tickets hotel and location details can be found in the faq home techniques enterprise stage capabilities drive by target stage capabilities drive by target other sub techniques of stage capabilities 6 id name t1608 001 upload malware t1608 002 upload tool t1608 003 install digital certificate t1608 004 drive by target t1608 005 link target t1608 006 seo poisoning adversaries may prepare an operational environment to infect systems that visit a website over the normal course of browsing endpoint systems may be compromised through browsing to adversary controlled sites as in drive by compromise in such cases the user s web browser is typically targeted for exploitation often not requiring any extra user interaction once landing on the site but adversaries may also set up websites for non exploitation behavior such as application access token prior to drive by compromise adversaries must stage resources needed to deliver that exploit to users who browse to an adversary controlled site drive by content can be staged on adversary controlled infrastructure that has been acquired acquire infrastructure or previously compromised compromise infrastructure adversaries may upload or inject malicious web content such as javascript into websites 1 2 this may be done in a number of ways including inserting malicious scripts into web pages or other user controllable web content such as forum posts modifying script files served to websites from publicly writeable cloud storage buckets crafting malicious web advertisements and purchasing ad space on a website through legitimate ad providers i e malvertising in addition to staging content to exploit a user s web browser adversaries may also stage scripting content to profile the user s browser as in gather victim host information to ensure it is vulnerable prior to attempting exploitation 3 websites compromised by an adversary and used to stage a drive by may be ones visited by a specific community such as government a particular industry or region where the goal is to compromise a specific user or set of users based on a shared interest this kind of targeted campaign is referred to a strategic web compromise or watering hole attack adversaries may purchase domains similar to legitimate domains ex homoglyphs typosquatting different top level domain etc during acquisition of infrastructure domains to help facilitate drive by compromise id t1608 004 sub technique of t1608 ⓘ tactic resource development ⓘ platforms pre version 1 3 created 17 march 2021 last modified 24 october 2025 version permalink live version procedure examples id name description g0050 apt32 apt32 has stood up websites containing numerous articles and content scraped from the internet to make them appear legitimate but some of these pages include malicious javascript to profile the potential victim or infect them via a fake software update 4 c0010 c0010 for c0010 the threat actors compromised the login page of a legitimate israeli shipping company and likely established a watering hole that collected visitor information 5 g1012 curium curium used strategic website compromise to fingerprint then target victims 6 g0035 dragonfly dragonfly has compromised websites to redirect traffic and to host exploit kits 7 g0046 fin7 fin7 has compromised a digital product website and modified multiple download links to point to trojanized versions of offered digital products 8 g1014 luminousmoth luminousmoth has redirected compromised machines to an actor controlled webpage through html injection 9 g1020 mustard tempest mustard tempest has injected malicious javascript into compromised websites to infect victims via drive by download 10 11 12 13 g0027 threat group 3390 threat group 3390 has embedded malicious code into websites to screen a potential victim s ip address and then exploit their browser if they are of interest 2 g0134 transparent tribe transparent tribe has set up websites with malicious hyperlinks and iframes to infect targeted victims with crimson njrat and other malicious tools 14 15 16 mitigations id mitigation description m1056 pre compromise this technique cannot be easily mitigated with preventive controls since it is based on behaviors performed outside of the scope of enterprise defenses and controls detection strategy id name analytic id analytic description det0825 detection of drive by target an1957 if infrastructure or patterns in the malicious web content utilized to deliver a drive by compromise have been previously identified internet scanning may uncover when an adversary has staged web content for use in a strategic web compromise much of this activity will take place outside the visibility of the target organization making detection of this behavior difficult detection efforts may be focused on other phases of the adversary lifecycle such as drive by compromise or exploitation for client execution references kindlund d 2012 december 30 cfr watering hole attack details retrieved november 17 2024 gallagher s 2015 august 5 newly discovered chinese hacking group hacked 100 websites to use as watering holes retrieved january 25 2016 blasco j 2014 august 28 scanbox a reconnaissance framework used with watering hole attacks retrieved october 19 2020 adair s and lancaster t 2020 november 6 oceanlotus extending cyber espionage operations through fake websites retrieved november 20 2020 mandiant israel research team 2022 august 17 suspected iranian actor targeting israeli shipping healthcare government and energy sectors retrieved september 21 2022 pwc threat intelligence 2023 october 25 yellow liderc ships its scripts and delivers imaploader malware retrieved august 14 2024 slowik j 2021 october the baffling berserk bear a decade s activity targeting critical infrastructure retrieved december 6 2021 abdo b et al 2022 april 4 fin7 power hour adversary archaeology and the evolution of fin7 retrieved april 5 2022 botezatu b and etl 2021 july 21 luminousmoth plugx file exfiltration and persistence revisited retrieved october 20 2022 andrew northern 2022 november 22 socgholish a very real threat from a very fake update retrieved february 13 2024 milenkoski a 2022 november 7 socgholish diversifies and expands its malware staging infrastructure to counter defenders retrieved march 22 2024 red canary 2024 march red canary 2024 threat detection report socgholish retrieved march 22 2024 secureworks n d gold prelude retrieved march 22 2024 huss d 2016 march 1 operation transparent tribe retrieved june 8 2016 falcone r and conant s 2016 march 25 projectm link found between pakistani actor and operation transparent tribe retrieved september 2 2021 malhotra a et al 2021 may 13 transparent tribe apt expands its windows malware arsenal retrieved september 2 2021 core objects all core att ck objects all none matrices tactics techniques sub techniques defenses all defenses all none mitigations assets detection strategies analytics data components cti all cti all none groups software campaigns reference all reference all none resources domains all domains all none enterprise mobile ics reset filters contact us terms of use privacy policy website changelog cookie preferences 2015 2026 the mitre corporation mitre att ck and att ck are registered trademarks of the mitre corporation
|