Rows marked inferred are OSINT-extracted enrichment for actors without a MITRE Group ID — treat as analyst assessment, not authoritative ATT&CK attribution.
| Technique | Name | Tactic | Observed use |
|---|---|---|---|
| T1005 ↗inferred | Data from Local System | Collection | steals documents from the host (Kaspersky) |
| T1056.001 ↗inferred | Input Capture: Keylogging | Collection | keylogging plugin (Kaspersky/CrySyS) |
| T1113 ↗inferred | Screen Capture | Collection | screen-capture module (Kaspersky) |
| T1123 ↗inferred | Audio Capture | Collection | records microphone audio (Kaspersky) |
| T1040 ↗inferred | Network Sniffing | Credential Access | sniffs network traffic (Kaspersky) |
| T1553.002 ↗inferred | Subvert Trust Controls: Code Signing | Defense Evasion | used a forged Microsoft certificate via MD5 chosen-prefix collision (Kaspersky) |
| T1070.004 ↗ |
| Indicator Removal: File Deletion |
| Defense Evasion |
| browse32 kill module wipes Flame from the system once exposed (Kaspersky) |
| T1120 ↗inferred | Peripheral Device Discovery | Discovery | scans for nearby Bluetooth devices (Kaspersky) |
| T1091 ↗inferred | Replication Through Removable Media | Lateral Movement | spreads and collects via infected USB drives (Kaspersky) |
Regional co-occurrence is association, not prediction. These techniques appeared alongside Flame / Flamer's activity across the tracked MENA roster — a TIE-style association computed on our corpus (not CTID's model), not a prediction of the next move. Ranked by support-adjusted lift (over-representation among actors like this one vs. the roster base rate, damped when few actors back it), so neither a merely-common technique nor a tiny-sample coincidence floats to the top. A hunting lead only; never recorded as observed. ICS techniques are excluded.
Which Microsoft 365 controls protect, detect, or respond to this actor's techniques — from the CTID Mappings Explorer (technique-level). Strength: significant / partial / minimal.
Defensive techniques that counter Flame / Flamer's TTPs, from MITRE D3FEND. The ATT&CK↔D3FEND link is mitigation-mediated — treat these as candidate countermeasures, not prescriptions.