Kill Chain & Diamond Model Analysis
Map a threat actor or campaign across the Cyber Kill Chain and Diamond Model of Intrusion.
Larva-208
(threat actor)
8 techniques
52 tools/malware
1 vulnerabilities
51 IOCs
2/7 stages covered
Deepest: Actions on Objectives
›
›
›
›
›
›
7
Actions on Objectives
8
T1036.001: Masquerading – System Software Name
T1041: Exfiltration Over Command and Control Channel
T1063: Permission Groups Discovery
T1110: Brute Force (Credential Access)
T1547: Boot or Logon Autostart Execution
Stage risk:
Critical
High
Medium
None
Indicators of Compromise (51)
ATT&CK Tactic Coverage
Reconnaissance
Resource Development
Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Command & Control
Exfiltration
Impact
Diamond Model of Intrusion
Adversary · Capability · Infrastructure · Victim
Larva-208
Type: Unknown Active
EncryptHub
aka Larva-208
Evil Corp
tracked as
ZDI-25-150
+5 more
8 technique(s) 52 tool(s)/malware 1 CVE(s)
Targeted Sectors
financial-services
defense
critical-infrastructure
Targeted Countries
RU
US
IR
Diamond Model Meta-Features
Phase
Actions on Objectives
Direction
Adversary → Infrastructure → Victim
Adversary → Capability
Adversary → Infrastructure
Capability → Victim
Infrastructure → Victim
Diamond Model edges