Rows marked inferred are OSINT-extracted enrichment for actors without a MITRE Group ID — treat as analyst assessment, not authoritative ATT&CK attribution.
| Technique | Name | Tactic | Observed use |
|---|---|---|---|
| T1090.001 ↗inferred | Internal Proxy | Command and Control | HYPERBRO and FOCUSFJORD configured as proxies relaying C2 through victim networks, with samples pointed at internal IPs (e.g., 192.168.1.237) to minimize external beaconing. |
| T1003.001 ↗inferred | LSASS Memory | Credential Access | Mimikatz deployed for credential extraction on compromised hosts; harvested credentials reused for lateral movement; tool removed after use. |
| T1574.001 ↗inferred | DLL | Defense Evasion | HYPERBRO and FOCUSFJORD stages loaded via DLL side-loading, per Mandiant's ATT&CK mapping for the UNC215 campaign. |
| T1562.001 ↗inferred | Disable or Modify Tools | Defense Evasion | After EDR/AV detections (April 2019-April 2020), UNC215 deployed anti.exe, which stops the Windows Update service and terminates EDR and antivirus services before redeploying updated HYPERBRO. |
| T1036 ↗inferred | Masquerading | Defense Evasion | False-flag tradecraft: FOCUSFJORD samples with auto-translated Farsi/Hindi registry keys and Arabic strings, reuse of the leaked Iranian SEASHARPEE web shell, and a Turkish lure with 'C:\Users\Iran' paths to misdirect attribution toward Iranian actors. |
| T1070.004 ↗inferred | File Deletion | Defense Evasion | Operators removed WHEATSCAN, Mimikatz and other tools after use and used FJORDOHELPER to fully uninstall FOCUSFJORD (files, registry config, persistence keys) to limit forensic evidence. |
| T1112 ↗inferred | Modify Registry | Defense Evasion | FOCUSFJORD stores up to 13 encrypted configuration values (group/console identifiers) in the registry to evade sandbox and automated analysis; FJORDOHELPER later removes them. |
| T1046 ↗inferred | Network Service Discovery | Discovery | Custom non-public scanner WHEATSCAN used for internal network reconnaissance, then deleted after use. |
| T1087 ↗inferred | Account Discovery | Discovery | ADFind and native Windows commands used to enumerate Active Directory accounts and domain structure post-compromise. |
| T1190 ↗inferred | Exploit Public-Facing Application | Initial Access | Mandiant 2021: UNC215 exploited Microsoft SharePoint CVE-2019-0604 from early 2019 to install web shells and FOCUSFJORD payloads on Israeli government and IT targets. |
| T1199 ↗inferred | Trusted Relationship | Initial Access | Mandiant reported UNC215 accessed Israeli government targets using stolen credentials and RDP from trusted third-party/IT provider environments it had already compromised. |
| T1021.001 ↗inferred | Remote Desktop Protocol | Lateral Movement | Stolen credentials used over RDP to move laterally within victim networks and from third-party environments into targets. |
| T1505.003 ↗inferred | Web Shell | Persistence | Web shells (including the leaked Iranian SEASHARPEE in April 2019) deployed on exploited SharePoint and compromised OWA servers for persistent access and credential harvesting. |
| T1547.001 ↗inferred | Registry Run Keys / Startup Folder | Persistence | FOCUSFJORD writes encrypted C2 config to the Windows registry and sets persistence via registry/service entries, then rewrites its own executable without the embedded config. |
Regional co-occurrence is association, not prediction. These techniques appeared alongside UNC215's activity across the tracked MENA roster — a TIE-style association computed on our corpus (not CTID's model), not a prediction of the next move. Ranked by support-adjusted lift (over-representation among actors like this one vs. the roster base rate, damped when few actors back it), so neither a merely-common technique nor a tiny-sample coincidence floats to the top. A hunting lead only; never recorded as observed. ICS techniques are excluded.
Which Microsoft 365 controls protect, detect, or respond to this actor's techniques — from the CTID Mappings Explorer (technique-level). Strength: significant / partial / minimal.
Defensive techniques that counter UNC215's TTPs, from MITRE D3FEND. The ATT&CK↔D3FEND link is mitigation-mediated — treat these as candidate countermeasures, not prescriptions.