Threat group.View on attack.mitre.org
Daggerfly is a People's Republic of China-linked APT entity active since at least 2012. Daggerfly has targeted individuals, government and NGO entities, and telecommunication companies in Asia and Africa. Daggerfly is associated with exclusive use of MgBot malware and is noted for several potential supply chain infection campaigns.
| Technique | Procedure example |
|---|---|
| T1003.002 Security Account Manager |
Daggerfly used Reg to dump the Security Account Manager (SAM) hive from victim machines for follow-on credential extraction. |
| T1012 Query Registry |
Daggerfly used Reg to dump the Security Account Manager (SAM), System, and Security Windows registry hives from victim machines. |
| T1036.003 Rename Legitimate Utilities |
Daggerfly used a renamed version of rundll32.exe, such as "dbengin.exe" located in the `ProgramData\Microsoft\PlayReady` directory, to proxy malicious DLL execution. |
| T1053.005 Scheduled Task |
Daggerfly has attempted to use scheduled tasks for persistence in victim environments. |
| T1059.001 PowerShell |
Daggerfly used PowerShell to download and execute remote-hosted files on victim systems. |
| T1071.001 Web Protocols |
Daggerfly uses HTTP for command and control communication. |
| T1082 System Information Discovery |
Daggerfly utilizes victim machine operating system information to create custom User Agent strings for subsequent command and control communication. |
| T1105 Ingress Tool Transfer |
Daggerfly has used PowerShell and BITSAdmin to retrieve follow-on payloads from external locations for execution on victim machines. |
| T1136.001 Local Account |
Daggerfly created a local account on victim machines to maintain access. |
| T1189 Drive-by Compromise |
Daggerfly has used strategic website compromise for initial access against victims. |
| T1195.002 Compromise Software Supply Chain |
Daggerfly is associated with several supply chain compromises using malicious updates to compromise victims. |
| T1204.001 Malicious Link |
Daggerfly has used strategic website compromise to deliver a malicious link requiring user interaction. |
| T1218.011 Rundll32 |
Daggerfly proxied execution of malicious DLLs through a renamed rundll32.exe binary. |
| T1553.002 Code Signing |
Daggerfly has used signed, but not notarized, malicious files for execution in macOS environments. |
| T1574.001 DLL |
Daggerfly has used legitimate software to side-load PlugX loaders onto victim systems. Daggerfly is also linked to multiple other instances of side-loading for initial loading activity. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.