Activity timeline
Forg365 operators appears in 2 tracked threats between and .
ATT&CK techniques observed
- T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 2 of 2 tracked threats
- T1071 Application Layer Protocol — Command and Controlobserved in 2 of 2 tracked threats
- T1087 Account Discovery — Discoveryobserved in 2 of 2 tracked threats
- T1090 Proxy — Command and Controlobserved in 2 of 2 tracked threats
- T1098 Account Manipulation — Persistenceobserved in 2 of 2 tracked threats
- T1111 Multi-Factor Authentication Interception — Credential Accessobserved in 2 of 2 tracked threats
- T1114 Email Collection — Collectionobserved in 2 of 2 tracked threats
- T1119 Automated Collection — Collectionobserved in 2 of 2 tracked threats
- T1176 Software Extensions — Persistenceobserved in 2 of 2 tracked threats
- T1213 Data from Information Repositories — Collectionobserved in 2 of 2 tracked threats
- T1497 Virtualization/Sandbox Evasion — Stealth (formerly Defense Evasion)observed in 2 of 2 tracked threats
- T1539 Steal Web Session Cookie — Credential Accessobserved in 2 of 2 tracked threats
- T1556 Modify Authentication Process — Defense Impairmentobserved in 2 of 2 tracked threats
- T1557 Adversary-in-the-Middle — Credential Accessobserved in 2 of 2 tracked threats
- T1566 Phishing — Initial Accessobserved in 2 of 2 tracked threats