ATT&CKGroupsMagic Hound

Magic Hound

G0059

Threat group.View on attack.mitre.org

About this group

Magic Hound is an Iranian-sponsored threat group that conducts long term, resource-intensive cyber espionage operations, likely on behalf of the Islamic Revolutionary Guard Corps. They have targeted European, U.S., and Middle Eastern government and military personnel, academics, journalists, and organizations such as the World Health Organization (WHO), via complex social engineering campaigns since at least 2014.

Techniques used78

Procedure examples78

TechniqueProcedure example
T1003.001
LSASS Memory

Magic Hound has stolen domain credentials by dumping LSASS process memory using Task Manager, comsvcs.dll, and from a Microsoft Active Directory Domain Controller using Mimikatz.

T1005
Data from Local System

Magic Hound has used a web shell to exfiltrate a ZIP file containing a dump of LSASS memory on a compromised machine.

T1016
System Network Configuration Discovery

Magic Hound malware gathers the victim's local IP address, MAC address, and external IP address.

T1016.001
Internet Connection Discovery

Magic Hound has conducted a network call out to a specific website as part of their initial discovery activity.

T1016.002
Wi-Fi Discovery

Magic Hound has collected names and passwords of all Wi-Fi networks to which a device has previously connected.

T1018
Remote System Discovery

Magic Hound has used Ping for discovery on targeted networks.

T1021.001
Remote Desktop Protocol

Magic Hound has used Remote Desktop Services to copy tools on targeted systems.

T1027.010
Command Obfuscation

Magic Hound has used base64-encoded commands.

T1027.013
Encrypted/Encoded File

Magic Hound malware has used base64-encoded files and has also encrypted embedded strings with AES.

T1033
System Owner/User Discovery

Magic Hound malware has obtained the victim username and sent it to the C2 server.

T1036.004
Masquerade Task or Service

Magic Hound has named a malicious script CacheTask.bat to mimic a legitimate task.

T1036.005
Match Legitimate Resource Name or Location

Magic Hound has used `dllhost.exe` to mask Fast Reverse Proxy (FRP) and `MicrosoftOutLookUpdater.exe` for Plink.

T1036.010
Masquerade Account Name

Magic Hound has created local accounts named `help` and `DefaultAccount` on compromised machines.

T1046
Network Service Discovery

Magic Hound has used KPortScan 3.0 to perform SMB, RDP, and LDAP scanning.

T1047
Windows Management Instrumentation

Magic Hound has used a tool to run `cmd /c wmic computersystem get domain` for discovery.

View all 78 procedure examples

Software13

Campaigns0

None recorded.

References5

  1. Certfa Charming Kitten January 2021 Open source
    Certfa Labs. (2021, January 8). Charming Kitten’s Christmas Gift. Retrieved May 3, 2021.
  2. ClearSky Kittens Back 3 August 2020 Open source
    ClearSky Research Team. (2020, August 1). The Kittens Are Back in Town 3 - Charming Kitten Campaign Evolved and Deploying Spear-Phishing link by WhatsApp. Retrieved April 21, 2021.
  3. FireEye APT35 2018 Open source
    Mandiant. (2018). Mandiant M-Trends 2018. Retrieved November 17, 2024.
  4. Proofpoint TA453 July2021 Open source
    Miller, J. et al. (2021, July 13). Operation SpoofedScholars: A Conversation with TA453. Retrieved August 18, 2021.
  5. Secureworks COBALT ILLUSION Threat Profile Open source
    Secureworks. (n.d.). COBALT ILLUSION Threat Profile. Retrieved April 14, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.