Campaign, Dec 2017 to Dec 2019.View on attack.mitre.org
Operation Wocao was a cyber espionage campaign that targeted organizations around the world, including in Brazil, China, France, Germany, Italy, Mexico, Portugal, Spain, the United Kingdom, and the United States. The suspected China-based actors compromised government organizations and managed service providers, as well as aviation, construction, energy, finance, health care, insurance, offshore engineering, software development, and transportation companies.
Security researchers assessed the Operation Wocao actors used similar TTPs and tools as APT20, suggesting a possible overlap. Operation Wocao was named after an observed command line entry by one of the threat actors, possibly out of frustration from losing webshell access.
| Technique | Procedure example |
|---|---|
| T1001 Data Obfuscation |
During Operation Wocao, threat actors encrypted IP addresses used for "Agent" proxy hops with RC4. |
| T1003.001 LSASS Memory |
During Operation Wocao, threat actors used ProcDump to dump credentials from memory. |
| T1003.006 DCSync |
During Operation Wocao, threat actors used Mimikatz's DCSync to dump credentials from the memory of the targeted system. |
| T1005 Data from Local System |
During Operation Wocao, threat actors exfiltrated files and directories of interest from the targeted system. |
| T1007 System Service Discovery |
During Operation Wocao, threat actors used the `tasklist` command to search for one of its backdoors. |
| T1012 Query Registry |
During Operation Wocao, the threat actors executed `/c cd /d c:\windows\temp\ & reg query HKEY_CURRENT_USER\Software\<username>\PuTTY\Sessions\` to detect recent PuTTY sessions, likely to further lateral movement. |
| T1016 System Network Configuration Discovery |
During Operation Wocao, threat actors discovered the local network configuration with `ipconfig`. |
| T1016.001 Internet Connection Discovery |
During Operation Wocao, threat actors used a Visual Basic script that checked for internet connectivity. |
| T1018 Remote System Discovery |
During Operation Wocao, threat actors used `nbtscan` and `ping` to discover remote systems, as well as `dsquery subnet` on a domain controller to retrieve all subnets in the Active Directory. |
| T1021.002 SMB/Windows Admin Shares |
During Operation Wocao, threat actors used Impacket's smbexec.py as well as accessing the C$ and IPC$ shares to move laterally. |
| T1027.005 Indicator Removal from Tools |
During Operation Wocao, threat actors edited variable names within the Impacket suite to avoid automated detection. |
| T1027.010 Command Obfuscation |
During Operation Wocao, threat actors executed PowerShell commands which were encoded or compressed using Base64, zlib, and XOR. |
| T1033 System Owner/User Discovery |
During Operation Wocao, threat actors enumerated sessions and users on a remote host, and identified privileged users logged into a targeted system. |
| T1036.005 Match Legitimate Resource Name or Location |
During Operation Wocao, the threat actors renamed some tools and executables to appear as legitimate programs. |
| T1041 Exfiltration Over C2 Channel |
During Operation Wocao, threat actors used the XServer backdoor to exfiltrate data. |
MITRE does not attribute this campaign to a group.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.