{ "type": "bundle", "id": "bundle--324d27b7-762d-42da-b0e4-86be5afc07c7", "objects": [ { "type": "attack-pattern", "spec_version": "2.1", "id": "attack-pattern--9b3efc53-3a9e-45e7-8a26-dd2c4a305fd2", "created_by_ref": "identity--f1a0f560-2d9e-4c5d-bf47-7e96e805de82", "created": "2022-07-03T23:52:02.916902Z", "modified": "2022-07-03T23:52:02.916902Z", "name": "Spoof/parody account/site", "description": "An influence operation may prepare assets impersonating legitimate entities to further conceal its network identity and add a layer of legitimacy to its operation content. Users will more likely believe and less likely fact-check news from recognizable sources rather than unknown sites. Legitimate entities may include authentic news outlets, public figures, organizations, or state entities. ", "kill_chain_phases": [ { "kill_chain_name": "mitre-attack", "phase_name": "establish-legitimacy" } ], "external_references": [ { "source_name": "mitre-attack", "url": "https://github.com/DISARMFoundation/DISARM_framework/blob/master/techniques/T0099.002.md", "external_id": "T0099.002" } ], "object_marking_refs": [ "marking-definition--f79f25d2-8b96-4580-b169-eb7b613a7c31" ], "x_mitre_is_subtechnique": true, "x_mitre_platforms": [ "Windows", "Linux", "Mac" ], "x_mitre_version": "2.1" } ] }