About this actor
[C0021](https://attack.mitre.org/campaigns/C0021) was a spearphishing campaign conducted in November 2018 that targeted public sector institutions, non-governmental organizations (NGOs), educational institutions, and private-sector corporations in the oil and gas, chemical, and hospitality industries. The majority of targets were located in the US, particularly in and around Washington D.C., with other targets located in Europe, Hong Kong, India, and Canada. [C0021](https://attack.mitre.org/campaigns/C0021)'s technical artifacts, tactics, techniques, and procedures (TTPs), and targeting overlap with previous suspected [APT29](https://attack.mitre.org/groups/G0016) activity.(Citation: Microsoft Unidentified Dec 2018)(Citation: FireEye APT29 Nov 2018)
Source: MITRE ATT&CK
How we know this
- Data origin
- MITRE ATT&CK campaign Imported from the MITRE ATT&CK STIX bundle as a campaign object.
- Techniques
- MITRE ATT&CK STIX mappings — 26 ATT&CK techniques on file.
- Named victims
- None on file.
See how actor data is built for the full pipeline.
Activity timeline
No activity events recorded.
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
| No attributed CVEs. | |||||
T1027Obfuscated Files or Information ↗T1027.009Embedded Payloads ↗T1027.010Command Obfuscation ↗T1059Command and Scripting Interpreter ↗T1059.001PowerShell ↗T1071Application Layer Protocol ↗T1071.001Web Protocols ↗T1095Non-Application Layer Protocol ↗T1105Ingress Tool Transfer ↗T1140Deobfuscate/Decode Files or Information ↗T1204User Execution ↗T1204.001Malicious Link ↗T1218System Binary Proxy Execution ↗T1218.011Rundll32 ↗T1566Phishing ↗T1566.002Spearphishing Link ↗T1573Encrypted Channel ↗T1573.002Asymmetric Cryptography ↗T1583Acquire Infrastructure ↗T1583.001Domains ↗T1584Compromise Infrastructure ↗T1584.001Domains ↗T1588Obtain Capabilities ↗T1588.002Tool ↗T1608Stage Capabilities ↗T1608.001Upload Malware ↗
Mitigating controls (NIST 800-53)
| Control | Techniques covered | Coverage |
|---|---|---|
SI-4 | 17 / 26 | 65% |
SI-3 | 16 / 26 | 62% |
CM-6 | 15 / 26 | 58% |
CM-2 | 14 / 26 | 54% |
CA-7 | 13 / 26 | 50% |
AC-4 | 11 / 26 | 42% |
CM-7 | 11 / 26 | 42% |
SC-7 | 11 / 26 | 42% |
SI-10 | 7 / 26 | 27% |
SI-2 | 7 / 26 | 27% |
SI-7 | 7 / 26 | 27% |
AC-3 | 5 / 26 | 19% |
IA-9 | 4 / 26 | 15% |
RA-5 | 4 / 26 | 15% |
SC-20 | 4 / 26 | 15% |
Co-occurring actors
None.
Similar actors
Similar TTPs
- LazyScripter 0.44
- Operation Spalax 0.43
- WIRTE 0.39
- BITTER 0.37
- TA505 0.35