Activity timeline
NetNut appears in 2 tracked threats between and .
ATT&CK techniques observed
- T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 2 of 2 tracked threats
- T1071 Application Layer Protocol — Command and Controlobserved in 2 of 2 tracked threats
- T1090 Proxy — Command and Controlobserved in 2 of 2 tracked threats
- T1102 Web Service — Command and Controlobserved in 2 of 2 tracked threats
- T1110 Brute Force — Credential Accessobserved in 2 of 2 tracked threats
- T1119 Automated Collection — Collectionobserved in 2 of 2 tracked threats
- T1195 Supply Chain Compromise — Initial Accessobserved in 2 of 2 tracked threats
- T1210 Exploitation of Remote Services — Lateral Movementobserved in 2 of 2 tracked threats
- T1496 Resource Hijacking — Impactobserved in 2 of 2 tracked threats
- T1498 Network Denial of Service — Impactobserved in 2 of 2 tracked threats
- T1547 Boot or Logon Autostart Execution — Persistenceobserved in 2 of 2 tracked threats
- T1568 Dynamic Resolution — Command and Controlobserved in 2 of 2 tracked threats
- T1573 Encrypted Channel — Command and Controlobserved in 2 of 2 tracked threats
- T1583 Acquire Infrastructure — Resource Developmentobserved in 2 of 2 tracked threats
- T1595 Active Scanning — Reconnaissanceobserved in 2 of 2 tracked threats