Microsoft Threat Intelligence. (2023, June 14). Cadet Blizzard emerges as a novel and distinct Russian threat actor. Retrieved July 10, 2023.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003 OS Credential Dumping |
GroupEmber Bear | Ember Bear gathers credential material from target systems, such as SSH keys, to facilitate access to victim environments. |
| T1003.001 LSASS Memory |
GroupEmber Bear | Ember Bear uses legitimate Sysinternals tools such as procdump to dump LSASS memory. |
| T1003.002 Security Account Manager |
GroupEmber Bear | Ember Bear acquires victim credentials by extracting registry hives such as the Security Account Manager through commands such as |
| T1005 Data from Local System |
GroupEmber Bear | Ember Bear gathers victim system information such as enumerating the volume of a given device or extracting system and security event logs for analysis. |
| T1021 Remote Services |
GroupEmber Bear | Ember Bear uses valid network credentials gathered through credential harvesting to move laterally within victim networks, often employing the Impacket framework to do so. |
| T1036 Masquerading |
GroupEmber Bear | Ember Bear has renamed the legitimate Sysinternals tool procdump to alternative names such as |
| T1053.005 Scheduled Task |
GroupEmber Bear | Ember Bear uses remotely scheduled tasks to facilitate remote command execution on victim machines. |
| T1070.004 File Deletion |
GroupEmber Bear | Ember Bear deletes files related to lateral movement to avoid detection. |
| T1095 Non-Application Layer Protocol |
GroupEmber Bear | Ember Bear uses socket-based tunneling utilities for command and control purposes such as NetCat and Go Simple Tunnel (GOST). These tunnels are used to push interactive command prompts over the created sockets. Ember Bear has also used reverse TCP connections from Meterpreter installations to communicate back with C2 infrastructure. |
| T1112 Modify Registry |
GroupEmber Bear | Ember Bear modifies registry values for anti-forensics and defense evasion purposes. |
| T1114 Email Collection |
GroupEmber Bear | Ember Bear attempts to collect mail from accessed systems and servers. |
| T1119 Automated Collection |
GroupEmber Bear | Ember Bear engages in mass collection from compromised systems during intrusions. |
| T1190 Exploit Public-Facing Application |
GroupEmber Bear | Ember Bear gains initial access to victim environments by exploiting external-facing services. Examples include exploitation of CVE-2021-26084 in Confluence servers; CVE-2022-41040, ProxyShell, and other vulnerabilities in Microsoft Exchange; and multiple vulnerabilities in open-source platforms such as content management systems. |
| T1195 Supply Chain Compromise |
GroupEmber Bear | Ember Bear has compromised information technology providers and software developers providing services to targets of interest, building initial access to ultimate victims at least in part through compromise of service providers that work with the victim organizations. |
| T1204.001 Malicious Link |
GroupSaint Bear | Saint Bear has, in addition to email-based phishing attachments, used malicious websites masquerading as legitimate entities to host links to malicious files for user execution. |
| T1491.002 External Defacement |
GroupEmber Bear | Ember Bear is linked to the defacement of several Ukrainian organization websites. |
| T1505.003 Web Shell |
MalwarereGeorg | reGeorg is a web shell that has been installed on exposed web servers for access to victim environments. |
| T1505.003 Web Shell |
GroupEmber Bear | Ember Bear deploys web shells following initial access for either follow-on command execution or protocol tunneling. Example web shells used by Ember Bear include P0wnyshell, reGeorg, P.A.S. Webshell, and custom variants of publicly-available web shell examples. |
| T1561.002 Disk Structure Wipe |
GroupEmber Bear | Ember Bear conducted destructive operations against victims, including disk structure wiping, via the WhisperGate malware in Ukraine. |
| T1570 Lateral Tool Transfer |
GroupEmber Bear | Ember Bear retrieves follow-on payloads direct from adversary-owned infrastructure for deployment on compromised hosts. |
| T1572 Protocol Tunneling |
MalwarereGeorg | reGeorg can tunnel TCP sessions including RDP, SSH, and SMB through HTTP. |
| T1583 Acquire Infrastructure |
GroupEmber Bear | Ember Bear uses services such as IVPN, SurfShark, and Tor to add anonymization to operations. |
| T1684.001 Impersonation |
GroupSaint Bear | Saint Bear has impersonated government and related entities in both phishing activity and developing web sites with malicious links that mimic legitimate resources. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.