MISP-Maltego Analysis Revisits Tropic Trooper TTPs
A methodology piece shows how MISP and Maltego visualisations reveal discrepancies between a Cylance report and MITRE ATT&CK data on Tropic Trooper's techniques.
This article is a technical methodology piece from the MISP Project demonstrating how to use MISP threat-sharing data combined with the Maltego visualisation tool to better analyse and cross-reference MITRE ATT&CK-tagged threat intelligence. Using a September 2019 Cylance report on 'PcShare Backdoor Attacks Targeting Windows Users with FakeNarrator Malware' as a case study, the authors show that manual comparison of technique lists is error-prone due to human working-memory limits, and that graph visualisation surfaces a much larger discrepancy than initially assumed between the ATT&CK techniques documented in the report versus those MITRE associates with the actor.
The case study centers on the threat actor Tropic Trooper (MITRE ID G0081), linked to the PcShare backdoor and FakeNarrator malware. The analysis found only 5 techniques in common between the Cylance report and MITRE's documentation, with 13 techniques unique to MITRE and 11 unique to the report — far more divergence than a surface reading suggested. The piece attributes this gap to incomplete actor knowledge at documentation time, evolving actor TTPs, subjective tagging practices, and the generic nature of some ATT&CK techniques (partially addressed by MITRE's sub-techniques initiative).
Overall, this is an informational/analyst-tooling article rather than a report of active threat activity. It carries no new IOCs, vulnerabilities, or campaign disclosures, and primarily serves to promote best practices for CTI analysts using MISP and Maltego to reconcile and visualise ATT&CK-tagged threat data across sources.
Mentioned in this report
Source reporting: https://www.misp-project.org/2019/10/27/visualising_common_patterns_attack.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free