Rows marked inferred are OSINT-extracted enrichment for actors without a MITRE Group ID — treat as analyst assessment, not authoritative ATT&CK attribution.
| Technique | Name | Tactic | Observed use |
|---|---|---|---|
| T1105 ↗inferred | Ingress Tool Transfer | Command and Control | downloads backdoor components and executes remote commands (ESET) |
| T1027 ↗inferred | Obfuscated Files or Information | Defense Evasion | Sponsor uses configuration files on disk to evade detection (ESET) |
| T1082 ↗inferred | System Information Discovery | Discovery | Sponsor implant collects host information (ESET) |
| T1059.003 ↗inferred | Command and Scripting Interpreter: Windows Command Shell | Execution | batch-file-driven staging of the Sponsor backdoor (ESET, batch-filed whiskers) |
| T1190 ↗inferred | Exploit Public-Facing Application | Initial Access | scan-and-strike exploitation of vulnerable internet-facing servers for initial access (ESET, Sponsoring Access) |
| T1543.003 ↗inferred | Create or Modify System Process: Windows Service |
| Persistence |
| Sponsor backdoor installed and persisted as a Windows service (ESET) |
| T1505.003 ↗inferred | Server Software Component: Web Shell | Persistence | deploys web shells on compromised internet-facing servers (ESET) |
Regional co-occurrence is association, not prediction. These techniques appeared alongside Ballistic Bobcat's activity across the tracked MENA roster — a TIE-style association computed on our corpus (not CTID's model), not a prediction of the next move. Ranked by support-adjusted lift (over-representation among actors like this one vs. the roster base rate, damped when few actors back it), so neither a merely-common technique nor a tiny-sample coincidence floats to the top. A hunting lead only; never recorded as observed. ICS techniques are excluded.
Which Microsoft 365 controls protect, detect, or respond to this actor's techniques — from the CTID Mappings Explorer (technique-level). Strength: significant / partial / minimal.
Defensive techniques that counter Ballistic Bobcat's TTPs, from MITRE D3FEND. The ATT&CK↔D3FEND link is mitigation-mediated — treat these as candidate countermeasures, not prescriptions.