C0011 C0011
C0011 was a suspected cyber espionage campaign conducted by Transparent Tribe that targeted students at universities and colleges in India. Security researchers noted this campaign against students was a significant shift from Transparent Tribe‘s historic targeting Indian government, military, and think tank personnel, and assessed it was still ongoing as of July 2022.1
Item | Value |
---|---|
ID | C0011 |
Associated Names | |
First Seen | December 2021 |
Last Seen | July 2022 |
Version | 1.0 |
Created | 22 September 2022 |
Last Modified | 22 September 2022 |
Navigation Layer | View In ATT&CK® Navigator |
Groups
ID | Name | References |
---|---|---|
G0134 | Transparent Tribe | 1 |
Techniques Used
Domain | ID | Name | Use |
---|---|---|---|
enterprise | T1583 | Acquire Infrastructure | - |
enterprise | T1583.001 | Domains | For C0011, Transparent Tribe registered domains likely designed to appear relevant to student targets in India.1 |
enterprise | T1059 | Command and Scripting Interpreter | - |
enterprise | T1059.005 | Visual Basic | For C0011, Transparent Tribe used malicious VBA macros within a lure document as part of the Crimson malware installation process onto a compromised host.1 |
enterprise | T1587 | Develop Capabilities | - |
enterprise | T1587.003 | Digital Certificates | For C0011, Transparent Tribe established SSL certificates on the typo-squatted domains the group registered.1 |
enterprise | T1566 | Phishing | - |
enterprise | T1566.001 | Spearphishing Attachment | During C0011, Transparent Tribe sent malicious attachments via email to student targets in India.1 |
enterprise | T1566.002 | Spearphishing Link | During C0011, Transparent Tribe sent emails containing a malicious link to student targets in India.1 |
enterprise | T1608 | Stage Capabilities | - |
enterprise | T1608.001 | Upload Malware | For C0011, Transparent Tribe hosted malicious documents on domains registered by the group.1 |
enterprise | T1204 | User Execution | - |
enterprise | T1204.001 | Malicious Link | During C0011, Transparent Tribe relied on student targets to click on a malicious link sent via email.1 |
enterprise | T1204.002 | Malicious File | During C0011, Transparent Tribe relied on a student target to open a malicious document delivered via email.1 |
Software
ID | Name | Description |
---|---|---|
S0115 | Crimson | For C0011, Transparent Tribe used an updated version of Crimson.1 |