Rows marked inferred are OSINT-extracted enrichment for actors without a MITRE Group ID — treat as analyst assessment, not authoritative ATT&CK attribution.
| Technique | Name | Tactic | Observed use |
|---|---|---|---|
| T1560.001 ↗inferred | Archive via Utility | Collection | Used WinRAR to archive collected data prior to exfiltration per CISA AA22-257A. |
| T1090 ↗inferred | Proxy | Command and Control | Used FRP/FRPC and a custom Go reverse-proxy (dllhost.exe), Plink and Ngrok for tunneled C2 per CISA AA22-257A and Secureworks. |
| T1003.001 ↗inferred | LSASS Memory | Credential Access | Dumped LSASS via rundll32 comsvcs.dll MiniDump with output reversed to ssasl.dmp per Microsoft DEV-0270. |
| T1112 ↗inferred | Modify Registry | Defense Evasion | Registry edits to enable WDigest UseLogonCredential, enable RDP (fDenyTSConnections=0) per Microsoft DEV-0270 report. |
| T1036.005 ↗inferred | Match Legitimate Resource Name or Location | Defense Evasion | Masqueraded binaries as dllhost.exe, task_update.exe, user.exe, CacheTask and renamed scanner as netscanold.exe per Microsoft and Secureworks. |
| T1562.001 ↗ |
+23 more relationships — see the relationships browser.
| Disable or Modify Tools |
| Defense Evasion |
| Disabled Microsoft Defender Antivirus real-time protection per Microsoft DEV-0270. |
| T1562.004 ↗inferred | Disable or Modify System Firewall | Defense Evasion | Added netsh advfirewall rule allowing inbound TCP 3389 (RDP) per Microsoft DEV-0270. |
| T1033 ↗inferred | System Owner/User Discovery | Discovery | Ran whoami, net user and wmic computersystem get domain for host/user discovery per Microsoft DEV-0270. |
| T1046 ↗inferred | Network Service Discovery | Discovery | Ran SoftPerfect Network Scanner for internal network reconnaissance per Secureworks and CISA AA22-257A. |
| T1059.001 ↗inferred | PowerShell | Execution | Used PowerShell for discovery and to force BitLocker encryption; Get-Recipient enumeration observed by Microsoft DEV-0270. |
| T1047 ↗inferred | Windows Management Instrumentation | Execution | Used compiled Impacket wmiexec.exe for remote command execution across the network per Microsoft and Secureworks. |
| T1567.002 ↗inferred | Exfiltration to Cloud Storage | Exfiltration | Cluster B uploaded stolen data to file-sharing services (filemail.com, ufile.io, mega.nz, easyupload.io) per Secureworks. |
| T1486 ↗inferred | Data Encrypted for Impact | Impact | Forced BitLocker activation and deployed DiskCryptor for full-disk encryption/extortion with ransom notes to printers per Microsoft, Secureworks and CISA AA22-257A. |
| T1190 ↗inferred | Exploit Public-Facing Application | Initial Access | Scan-and-exploit of Exchange ProxyShell (CVE-2021-34473/34523/31207), Fortinet FortiOS (CVE-2018-13379) and Log4Shell (CVE-2021-44228) on VMware Horizon per CISA AA22-257A, Microsoft and Secureworks. |
| T1021.001 ↗inferred | Remote Desktop Protocol | Lateral Movement | Enabled and used RDP with DefaultAccount for lateral movement and tool deployment per Microsoft and Secureworks. |
| T1136.001 ↗inferred | Local Account | Persistence | Created local accounts (DefaultAccount password P@ssw0rd1234, MSSQL user) via net user /add per Microsoft and Secureworks. |
| T1053.005 ↗inferred | Scheduled Task | Persistence | Created scheduled tasks via XML (Wininet.xml, SynchronizeTimeZone.xml) running .bat files that download renamed FRP proxy per Microsoft and CISA AA22-257A. |
| T1505.003 ↗inferred | Web Shell | Persistence | Deployed ASPX web shells (filename pattern aspx_[a-z]{13}.aspx) after exploiting Exchange/IIS per Secureworks Cobalt Mirage. |
Regional co-occurrence is association, not prediction. These techniques appeared alongside Nemesis Kitten's activity across the tracked MENA roster — a TIE-style association computed on our corpus (not CTID's model), not a prediction of the next move. Ranked by support-adjusted lift (over-representation among actors like this one vs. the roster base rate, damped when few actors back it), so neither a merely-common technique nor a tiny-sample coincidence floats to the top. A hunting lead only; never recorded as observed. ICS techniques are excluded.
Which Microsoft 365 controls protect, detect, or respond to this actor's techniques — from the CTID Mappings Explorer (technique-level). Strength: significant / partial / minimal.
Defensive techniques that counter Nemesis Kitten's TTPs, from MITRE D3FEND. The ATT&CK↔D3FEND link is mitigation-mediated — treat these as candidate countermeasures, not prescriptions.