Skip to content

Hide Navigation Hide TOC

Bouncing Golf - G0097 (049cef3b-22d5-4be6-b50c-9839c7a34fdd)

Bouncing Golf is a cyberespionage campaign targeting Middle Eastern countries.(Citation: Trend Micro Bouncing Golf 2019)

Cluster A Galaxy A Cluster B Galaxy B Level
Bouncing Golf - G0097 (049cef3b-22d5-4be6-b50c-9839c7a34fdd) Intrusion Set GolfSpy - S0421 (c19cfc89-5ac6-4d2d-a236-70d2b32e007c) Malware 1
Bouncing Golf - G0097 (049cef3b-22d5-4be6-b50c-9839c7a34fdd) Intrusion Set Match Legitimate Name or Location - T1655.001 (114fed8b-7eed-4136-8b9c-411c5c7fff4b) Attack Pattern 1
Archive Collected Data - T1532 (e3b936a4-6321-4172-9114-038a866362ec) Attack Pattern GolfSpy - S0421 (c19cfc89-5ac6-4d2d-a236-70d2b32e007c) Malware 2
System Information Discovery - T1426 (e2ea7f6b-8d4f-49c3-819d-660530d12b77) Attack Pattern GolfSpy - S0421 (c19cfc89-5ac6-4d2d-a236-70d2b32e007c) Malware 2
Software Discovery - T1418 (198ce408-1470-45ee-b47f-7056050d4fc2) Attack Pattern GolfSpy - S0421 (c19cfc89-5ac6-4d2d-a236-70d2b32e007c) Malware 2
Call Log - T1636.002 (1d1b1558-c833-482e-aabb-d07ef6eae63d) Attack Pattern GolfSpy - S0421 (c19cfc89-5ac6-4d2d-a236-70d2b32e007c) Malware 2
Data from Local System - T1533 (e1c912a9-e305-434b-9172-8a6ce3ec9c4a) Attack Pattern GolfSpy - S0421 (c19cfc89-5ac6-4d2d-a236-70d2b32e007c) Malware 2
Process Discovery - T1424 (1b51f5bc-b97a-498a-8dbd-bc6b1901bf19) Attack Pattern GolfSpy - S0421 (c19cfc89-5ac6-4d2d-a236-70d2b32e007c) Malware 2
Location Tracking - T1430 (99e6295e-741b-4857-b6e5-64989eb039b4) Attack Pattern GolfSpy - S0421 (c19cfc89-5ac6-4d2d-a236-70d2b32e007c) Malware 2
Clipboard Data - T1414 (c4b96c0b-cb58-497a-a1c2-bb447d79d692) Attack Pattern GolfSpy - S0421 (c19cfc89-5ac6-4d2d-a236-70d2b32e007c) Malware 2
GolfSpy - S0421 (c19cfc89-5ac6-4d2d-a236-70d2b32e007c) Malware Audio Capture - T1429 (6683aa0c-d98a-4f5b-ac57-ca7e9934a760) Attack Pattern 2
Contact List - T1636.003 (e0b9ecb8-a7d1-43c7-aa30-8e19c6a92c86) Attack Pattern GolfSpy - S0421 (c19cfc89-5ac6-4d2d-a236-70d2b32e007c) Malware 2
File Deletion - T1630.002 (ab7400b7-3476-4776-9545-ef3fa373de63) Attack Pattern GolfSpy - S0421 (c19cfc89-5ac6-4d2d-a236-70d2b32e007c) Malware 2
Screen Capture - T1513 (73c26732-6422-4081-8b63-6d0ae93d449e) Attack Pattern GolfSpy - S0421 (c19cfc89-5ac6-4d2d-a236-70d2b32e007c) Malware 2
Exfiltration Over C2 Channel - T1646 (32063d7f-0a39-440d-a4a3-2694488f96cc) Attack Pattern GolfSpy - S0421 (c19cfc89-5ac6-4d2d-a236-70d2b32e007c) Malware 2
GolfSpy - S0421 (c19cfc89-5ac6-4d2d-a236-70d2b32e007c) Malware Broadcast Receivers - T1624.001 (3775a580-a1d1-46c4-8147-c614a715f2e9) Attack Pattern 2
Video Capture - T1512 (d8940e76-f9c1-4912-bea6-e21c251370b6) Attack Pattern GolfSpy - S0421 (c19cfc89-5ac6-4d2d-a236-70d2b32e007c) Malware 2
Obfuscated Files or Information - T1406 (d13fa042-8f26-44e1-a2a8-af0bf8e2ac9a) Attack Pattern GolfSpy - S0421 (c19cfc89-5ac6-4d2d-a236-70d2b32e007c) Malware 2
SMS Messages - T1636.004 (c6421411-ae61-42bb-9098-73fddb315002) Attack Pattern GolfSpy - S0421 (c19cfc89-5ac6-4d2d-a236-70d2b32e007c) Malware 2
Masquerading - T1655 (f856eaab-e84a-4265-a8a2-7bf37e5dc2fc) Attack Pattern Match Legitimate Name or Location - T1655.001 (114fed8b-7eed-4136-8b9c-411c5c7fff4b) Attack Pattern 2
Protected User Data - T1636 (11c2c2b7-1fd4-408f-bc2e-fe772ef9df5e) Attack Pattern Call Log - T1636.002 (1d1b1558-c833-482e-aabb-d07ef6eae63d) Attack Pattern 3
Protected User Data - T1636 (11c2c2b7-1fd4-408f-bc2e-fe772ef9df5e) Attack Pattern Contact List - T1636.003 (e0b9ecb8-a7d1-43c7-aa30-8e19c6a92c86) Attack Pattern 3
File Deletion - T1630.002 (ab7400b7-3476-4776-9545-ef3fa373de63) Attack Pattern Indicator Removal on Host - T1630 (0d4e3bbb-7af5-4c88-a215-0c0906bc1e8d) Attack Pattern 3
Event Triggered Execution - T1624 (d446b9f0-06a9-4a8d-97ee-298cfee84f14) Attack Pattern Broadcast Receivers - T1624.001 (3775a580-a1d1-46c4-8147-c614a715f2e9) Attack Pattern 3
Protected User Data - T1636 (11c2c2b7-1fd4-408f-bc2e-fe772ef9df5e) Attack Pattern SMS Messages - T1636.004 (c6421411-ae61-42bb-9098-73fddb315002) Attack Pattern 3