ATT&CKReferencesCadet Blizzard emerges as novel threat actor

Cadet Blizzard emerges as novel threat actor

Microsoft Threat Intelligence. (2023, June 14). Cadet Blizzard emerges as a novel and distinct Russian threat actor. Retrieved July 10, 2023.

Open the source

Techniques1

Groups2

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples23

TechniqueUsed byProcedure example
T1003
OS Credential Dumping
GroupEmber Bear

Ember Bear gathers credential material from target systems, such as SSH keys, to facilitate access to victim environments.

T1003.001
LSASS Memory
GroupEmber Bear

Ember Bear uses legitimate Sysinternals tools such as procdump to dump LSASS memory.

T1003.002
Security Account Manager
GroupEmber Bear

Ember Bear acquires victim credentials by extracting registry hives such as the Security Account Manager through commands such as reg save.

T1005
Data from Local System
GroupEmber Bear

Ember Bear gathers victim system information such as enumerating the volume of a given device or extracting system and security event logs for analysis.

T1021
Remote Services
GroupEmber Bear

Ember Bear uses valid network credentials gathered through credential harvesting to move laterally within victim networks, often employing the Impacket framework to do so.

T1036
Masquerading
GroupEmber Bear

Ember Bear has renamed the legitimate Sysinternals tool procdump to alternative names such as dump64.exe to evade detection.

T1053.005
Scheduled Task
GroupEmber Bear

Ember Bear uses remotely scheduled tasks to facilitate remote command execution on victim machines.

T1070.004
File Deletion
GroupEmber Bear

Ember Bear deletes files related to lateral movement to avoid detection.

T1095
Non-Application Layer Protocol
GroupEmber Bear

Ember Bear uses socket-based tunneling utilities for command and control purposes such as NetCat and Go Simple Tunnel (GOST). These tunnels are used to push interactive command prompts over the created sockets. Ember Bear has also used reverse TCP connections from Meterpreter installations to communicate back with C2 infrastructure.

T1112
Modify Registry
GroupEmber Bear

Ember Bear modifies registry values for anti-forensics and defense evasion purposes.

T1114
Email Collection
GroupEmber Bear

Ember Bear attempts to collect mail from accessed systems and servers.

T1119
Automated Collection
GroupEmber Bear

Ember Bear engages in mass collection from compromised systems during intrusions.

T1190
Exploit Public-Facing Application
GroupEmber Bear

Ember Bear gains initial access to victim environments by exploiting external-facing services. Examples include exploitation of CVE-2021-26084 in Confluence servers; CVE-2022-41040, ProxyShell, and other vulnerabilities in Microsoft Exchange; and multiple vulnerabilities in open-source platforms such as content management systems.

T1195
Supply Chain Compromise
GroupEmber Bear

Ember Bear has compromised information technology providers and software developers providing services to targets of interest, building initial access to ultimate victims at least in part through compromise of service providers that work with the victim organizations.

T1204.001
Malicious Link
GroupSaint Bear

Saint Bear has, in addition to email-based phishing attachments, used malicious websites masquerading as legitimate entities to host links to malicious files for user execution.

T1491.002
External Defacement
GroupEmber Bear

Ember Bear is linked to the defacement of several Ukrainian organization websites.

T1505.003
Web Shell
MalwarereGeorg

reGeorg is a web shell that has been installed on exposed web servers for access to victim environments.

T1505.003
Web Shell
GroupEmber Bear

Ember Bear deploys web shells following initial access for either follow-on command execution or protocol tunneling. Example web shells used by Ember Bear include P0wnyshell, reGeorg, P.A.S. Webshell, and custom variants of publicly-available web shell examples.

T1561.002
Disk Structure Wipe
GroupEmber Bear

Ember Bear conducted destructive operations against victims, including disk structure wiping, via the WhisperGate malware in Ukraine.

T1570
Lateral Tool Transfer
GroupEmber Bear

Ember Bear retrieves follow-on payloads direct from adversary-owned infrastructure for deployment on compromised hosts.

T1572
Protocol Tunneling
MalwarereGeorg

reGeorg can tunnel TCP sessions including RDP, SSH, and SMB through HTTP.

T1583
Acquire Infrastructure
GroupEmber Bear

Ember Bear uses services such as IVPN, SurfShark, and Tor to add anonymization to operations.

T1684.001
Impersonation
GroupSaint Bear

Saint Bear has impersonated government and related entities in both phishing activity and developing web sites with malicious links that mimic legitimate resources.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.