ATT&CKCampaignsOperation Ghost

Operation Ghost

C0023

Campaign, Sep 2013 to Oct 2019.View on attack.mitre.org

About this campaign

Operation Ghost was an APT29 campaign starting in 2013 that included operations against ministries of foreign affairs in Europe and the Washington, D.C. embassy of a European Union country. During Operation Ghost, APT29 used new families of malware and leveraged web services, steganography, and unique C2 infrastructure for each victim.

Techniques used8

Procedure examples8

TechniqueProcedure example
T1001.002
Steganography

During Operation Ghost, APT29 used steganography to hide the communications between the implants and their C&C servers.

T1027.003
Steganography

During Operation Ghost, APT29 used steganography to hide payloads inside valid images.

T1078.002
Domain Accounts

For Operation Ghost, APT29 used stolen administrator credentials for lateral movement on compromised networks.

T1102.002
Bidirectional Communication

For Operation Ghost, APT29 used social media platforms to hide communications to C2 servers.

T1546.003
Windows Management Instrumentation Event Subscription

During Operation Ghost, APT29 used WMI event subscriptions to establish persistence for malware.

T1583.001
Domains

For Operation Ghost, APT29 registered domains for use in C2 including some crafted to appear as existing legitimate domains.

T1585.001
Social Media Accounts

For Operation Ghost, APT29 registered Twitter accounts to host C2 nodes.

T1587.001
Malware

For Operation Ghost, APT29 used new strains of malware including FatDuke, MiniDuke, RegDuke, and PolyglotDuke.

Attributed groups1

Software5

References1

  1. ESET Dukes October 2019 Open source
    Faou, M., Tartare, M., Dupuy, T. (2019, October). OPERATION GHOST. Retrieved September 23, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.