ATT&CKGroupsInception

Inception

G0100

Threat group.View on attack.mitre.org

About this group

Inception is a cyber espionage group active since at least 2014. The group has targeted multiple industries and governmental entities primarily in Russia, but has also been active in the United States and throughout Europe, Asia, Africa, and the Middle East.

Techniques used22

Procedure examples22

TechniqueProcedure example
T1005
Data from Local System

Inception used a file hunting plugin to collect .txt, .pdf, .xls or .doc files from the infected host.

T1027.013
Encrypted/Encoded File

Inception has encrypted malware payloads dropped on victim machines with AES and RC4 encryption.

T1057
Process Discovery

Inception has used a reconnaissance module to identify active processes and other associated loaded modules.

T1059.001
PowerShell

Inception has used PowerShell to execute malicious commands and payloads.

T1059.005
Visual Basic

Inception has used VBScript to execute malicious commands and payloads.

T1069.002
Domain Groups

Inception has used specific malware modules to gather domain membership.

T1071.001
Web Protocols

Inception has used HTTP, HTTPS, and WebDav in network communications.

T1082
System Information Discovery

Inception has used a reconnaissance module to gather information about the operating system and hardware on the infected host.

T1083
File and Directory Discovery

Inception used a file listing plugin to collect information about file and directories both on local and remote drives.

T1090.003
Multi-hop Proxy

Inception used chains of compromised routers to proxy C2 communications between them and cloud service providers.

T1102
Web Service

Inception has incorporated at least five different cloud service providers into their C2 infrastructure including CloudMe.

T1203
Exploitation for Client Execution

Inception has exploited CVE-2012-0158, CVE-2014-1761, CVE-2017-11882 and CVE-2018-0802 for execution.

T1204.002
Malicious File

Inception lured victims into clicking malicious files for machine reconnaissance and to execute malware.

T1218.005
Mshta

Inception has used malicious HTA files to drop and execute malware.

T1218.010
Regsvr32

Inception has ensured persistence at system boot by setting the value regsvr32 %path%\ctfmonrn.dll /s.

View all 22 procedure examples

Software3

Campaigns0

None recorded.

References3

  1. Kaspersky Cloud Atlas December 2014 Open source
    GReAT. (2014, December 10). Cloud Atlas: RedOctober APT is back in style. Retrieved May 8, 2020.
  2. Symantec Inception Framework March 2018 Open source
    Symantec. (2018, March 14). Inception Framework: Alive and Well, and Hiding Behind Proxies. Retrieved May 8, 2020.
  3. Unit 42 Inception November 2018 Open source
    Lancaster, T. (2018, November 5). Inception Attackers Target Europe with Year-old Office Vulnerability. Retrieved May 8, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.