C0018

C0018

Campaign, Feb 2022 to Mar 2022.View on attack.mitre.org

About this campaign

C0018 was a month-long ransomware intrusion that successfully deployed AvosLocker onto a compromised network. The unidentified actors gained initial access to the victim network through an exposed server and used a variety of open-source tools prior to executing AvosLocker.

Techniques used19

Procedure examples19

TechniqueProcedure example
T1016
System Network Configuration Discovery

During C0018, the threat actors ran `nslookup` and Advanced IP Scanner on the target network.

T1021.001
Remote Desktop Protocol

During C0018, the threat actors opened a variety of ports to establish RDP connections, including ports 28035, 32467, 41578, and 46892.

T1027.010
Command Obfuscation

During C0018, the threat actors used Base64 to encode their PowerShell scripts.

T1033
System Owner/User Discovery

During C0018, the threat actors collected `whoami` information via PowerShell scripts.

T1036
Masquerading

During C0018, AvosLocker was disguised using the victim company name as the filename.

T1036.005
Match Legitimate Resource Name or Location

For C0018, the threat actors renamed a Sliver payload to `vmware_kb.exe`.

T1046
Network Service Discovery

During C0018, the threat actors used the SoftPerfect Network Scanner for network scanning.

T1047
Windows Management Instrumentation

During C0018, the threat actors used WMIC to modify administrative settings on both a local and a remote host, likely as part of the first stages for their lateral movement; they also used WMI Provider Host (`wmiprvse.exe`) to execute a variety of encoded PowerShell scripts using the `DownloadString` method.

T1059.001
PowerShell

During C0018, the threat actors used encoded PowerShell scripts for execution.

T1071.001
Web Protocols

During C0018, the threat actors used HTTP for C2 communications.

T1072
Software Deployment Tools

During C0018, the threat actors used PDQ Deploy to move AvosLocker and tools across the network.

T1105
Ingress Tool Transfer

During C0018, the threat actors downloaded additional tools, such as Mimikatz and Sliver, as well as Cobalt Strike and AvosLocker ransomware onto the victim network.

T1190
Exploit Public-Facing Application

During C0018, the threat actors exploited VMWare Horizon Unified Access Gateways that were vulnerable to several Log4Shell vulnerabilities, including CVE-2021-44228, CVE-2021-45046, CVE-2021-45105, and CVE-2021-44832.

T1218.011
Rundll32

During C0018, the threat actors used `rundll32` to run Mimikatz.

T1219.002
Remote Desktop Software

During C0018, the threat actors used AnyDesk to transfer tools between systems.

View all 19 procedure examples

Attributed groups0

MITRE does not attribute this campaign to a group.

Software6

References2

  1. Cisco Talos Avos Jun 2022 Open source
    Venere, G. Neal, C. (2022, June 21). Avos ransomware group expands with new attack arsenal. Retrieved January 11, 2023.
  2. Costa AvosLocker May 2022 Open source
    Costa, F. (2022, May 1). RaaS AvosLocker Incident Response Analysis. Retrieved January 11, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.