Rows marked inferred are OSINT-extracted enrichment for actors without a MITRE Group ID — treat as analyst assessment, not authoritative ATT&CK attribution.
| Technique | Name | Tactic | Observed use |
|---|---|---|---|
| T1005 ↗inferred | Data from Local System | Collection | FIONA/SONIA transfer files to/from victim; data-collection routine gathers computer name, network adapters, ARP table, loaded modules and file listings of key folders (Kaspersky). |
| T1113 ↗inferred | Screen Capture | Collection | BARBARA command (v5.00) captures the desktop/foreground window as BMP, PPMd-compresses it and sends to C2 (Kaspersky). |
| T1573.001 ↗inferred | Encrypted Channel: Symmetric Cryptography | Command and Control | C2 traffic wrapped in a 10-byte XOR key layer plus one-two layers of Twofish encryption (Kaspersky). |
| T1071.001 ↗inferred | Application Layer Protocol: Web Protocols | Command and Control | C2 over HTTP POST to hardcoded servers at /cgi-bin/feed.cgi and /cgi-bin/counter.cgi, request/reply carried in POST body (Kaspersky). |
| T1070.006 ↗inferred | Indicator Removal: Timestomp | Defense Evasion | RegisterService installer sets the creation time of the dropped icsvnt32.ocx to match %windir%\system32\kernel32.dll (Kaspersky). |
| T1010 ↗inferred | Application Window Discovery | Discovery | BARBARA only screenshots when the foreground window belongs to a hardcoded process list (Iexplore, Outlook, Winword, mstsc, Putty, etc.) (Kaspersky). |
| T1518.001 ↗inferred | Software Discovery: Security Software Discovery | Discovery | Checks for running AV processes outpost.exe, bdagent.exe and antivirus.exe and exits/disinfects if present (Kaspersky). |
| T1129 ↗inferred | Shared Modules | Execution | Runs as a DLL/OCX proxy loaded into svchost.exe/explorer.exe host processes; EVE command loads a specified DLL and executes its export (Kaspersky). |
| T1106 ↗inferred | Native API | Execution | ELVIS backdoor command creates a new process with given parameters and waits for it (Kaspersky command set). |
| T1041 ↗inferred | Exfiltration Over C2 Channel | Exfiltration | SONIA uploads collected files and command logs to the C2 inside the encrypted HTTP POST body (Kaspersky). |
| T1091 ↗inferred | Replication Through Removable Media | Lateral Movement | icsvntu32.ocx USB infector writes .thumbs.db, System32.dat payload and .Backup0D-.Backup0M dirs with target.lnk LNK exploit to spread via removable drives (Kaspersky). |
| T1546.015 ↗inferred | Event Triggered Execution: Component Object Model Hijacking | Persistence | Overwrites CLSID {4E14FBA2-2E22-11D1-9964-00C04FBBB345} InprocServer32 default to icsvnt32.ocx so a system COM object loads it into most processes at startup (Kaspersky). |
Regional co-occurrence is association, not prediction. These techniques appeared alongside miniFlame (SPE)'s activity across the tracked MENA roster — a TIE-style association computed on our corpus (not CTID's model), not a prediction of the next move. Ranked by support-adjusted lift (over-representation among actors like this one vs. the roster base rate, damped when few actors back it), so neither a merely-common technique nor a tiny-sample coincidence floats to the top. A hunting lead only; never recorded as observed. ICS techniques are excluded.
Which Microsoft 365 controls protect, detect, or respond to this actor's techniques — from the CTID Mappings Explorer (technique-level). Strength: significant / partial / minimal.
Defensive techniques that counter miniFlame (SPE)'s TTPs, from MITRE D3FEND. The ATT&CK↔D3FEND link is mitigation-mediated — treat these as candidate countermeasures, not prescriptions.