Threat group.View on attack.mitre.org
menuPass is a threat group that has been active since at least 2006. Individual members of menuPass are known to have acted in association with the Chinese Ministry of State Security's (MSS) Tianjin State Security Bureau and worked for the Huaying Haitai Science and Technology Development Company.
menuPass has targeted healthcare, defense, aerospace, finance, maritime, biotechnology, energy, and government sectors globally, with an emphasis on Japanese organizations. In 2016 and 2017, the group is known to have targeted managed IT service providers (MSPs), manufacturing and mining companies, and a university.
| Technique | Procedure example |
|---|---|
| T1003.002 Security Account Manager |
menuPass has used a modified version of pentesting tools wmiexec.vbs and secretsdump.py to dump credentials. |
| T1003.003 NTDS |
menuPass has used Ntdsutil to dump credentials. |
| T1003.004 LSA Secrets |
menuPass has used a modified version of pentesting tools wmiexec.vbs and secretsdump.py to dump credentials. |
| T1005 Data from Local System |
menuPass has collected various files from the compromised computers. |
| T1016 System Network Configuration Discovery |
menuPass has used several tools to scan for open NetBIOS nameservers and enumerate NetBIOS sessions. |
| T1018 Remote System Discovery |
menuPass uses scripts to enumerate IP ranges on the victim network. menuPass has also issued the command |
| T1021.001 Remote Desktop Protocol |
menuPass has used RDP connections to move across the victim network. |
| T1021.004 SSH |
menuPass has used Putty Secure Copy Client (PSCP) to transfer data. |
| T1027.013 Encrypted/Encoded File |
menuPass has encoded strings in its malware with base64 as well as with a simple, single-byte XOR obfuscation using key 0x40. |
| T1036 Masquerading |
menuPass has used esentutl to change file extensions to their true type that were masquerading as .txt files. |
| T1036.003 Rename Legitimate Utilities |
menuPass has renamed certutil and moved it to a different location on the system to avoid detection based on use of the tool. |
| T1036.005 Match Legitimate Resource Name or Location |
menuPass has been seen changing malicious files to appear legitimate. |
| T1039 Data from Network Shared Drive |
menuPass has collected data from remote systems by mounting network shares with |
| T1046 Network Service Discovery |
menuPass has used tcping.exe, similar to Ping, to probe port status on systems of interest. |
| T1047 Windows Management Instrumentation |
menuPass has used a modified version of pentesting script wmiexec.vbs, which logs into a remote machine using WMI. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.