US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.002 Security Account Manager |
GroupDragonfly | Dragonfly has dropped and executed SecretsDump to dump password hashes. |
| T1003.003 NTDS |
GroupDragonfly | Dragonfly has dropped and executed SecretsDump to dump password hashes. They also obtained ntds.dit from domain controllers. |
| T1003.004 LSA Secrets |
GroupDragonfly | Dragonfly has dropped and executed SecretsDump to dump password hashes. |
| T1005 Data from Local System |
GroupDragonfly | Dragonfly has collected data from local victim systems. |
| T1012 Query Registry |
GroupDragonfly | Dragonfly has queried the Registry to identify victim information. |
| T1016 System Network Configuration Discovery |
GroupDragonfly | Dragonfly has used batch scripts to enumerate network information, including information about trusts, zones, and the domain. |
| T1018 Remote System Discovery |
GroupDragonfly | Dragonfly has likely obtained a list of hosts in the victim environment. |
| T1021.001 Remote Desktop Protocol |
GroupDragonfly | Dragonfly has moved laterally via RDP. |
| T1033 System Owner/User Discovery |
GroupDragonfly | Dragonfly used the command |
| T1036.010 Masquerade Account Name |
GroupDragonfly | Dragonfly has created accounts disguised as legitimate backup and service accounts as well as an email administration account. |
| T1053.005 Scheduled Task |
GroupDragonfly | Dragonfly has used scheduled tasks to automatically log out of created accounts every 8 hours as well as to execute malicious files. |
| T1059 Command and Scripting Interpreter |
GroupDragonfly | Dragonfly has used the command line for execution. |
| T1059.001 PowerShell |
GroupDragonfly | Dragonfly has used PowerShell scripts for execution. |
| T1059.003 Windows Command Shell |
GroupDragonfly | Dragonfly has used various types of scripting to perform operations, including batch scripts. |
| T1059.006 Python |
GroupDragonfly | Dragonfly has used various types of scripting to perform operations, including Python scripts. The group was observed installing Python 2.7 on a victim. |
| T1069.002 Domain Groups |
GroupDragonfly | Dragonfly has used batch scripts to enumerate administrators and users in the domain. |
| T1070.004 File Deletion |
GroupDragonfly | Dragonfly has deleted many of its files used during operations as part of cleanup, including removing applications and deleting screenshots. |
| T1071.002 File Transfer Protocols |
GroupDragonfly | Dragonfly has used SMB for C2. |
| T1074.001 Local Data Staging |
GroupDragonfly | Dragonfly has created a directory named "out" in the user's %AppData% folder and copied files to it. |
| T1078 Valid Accounts |
GroupDragonfly | Dragonfly has compromised user credentials and used valid accounts for operations. |
| T1083 File and Directory Discovery |
GroupDragonfly | Dragonfly has used a batch script to gather folder and file names from victim hosts. |
| T1087.002 Domain Account |
GroupDragonfly | Dragonfly has used batch scripts to enumerate users on a victim domain controller. |
| T1098.007 Additional Local or Domain Groups |
GroupDragonfly | Dragonfly has added newly created accounts to the administrators group to maintain elevated access. |
| T1105 Ingress Tool Transfer |
GroupDragonfly | Dragonfly has copied and installed tools for operations once in the victim environment. |
| T1110.002 Password Cracking |
GroupDragonfly | Dragonfly has dropped and executed tools used for password cracking, including Hydra and CrackMapExec. |
| T1112 Modify Registry |
GroupDragonfly | Dragonfly has modified the Registry to perform multiple techniques through the use of Reg. |
| T1113 Screen Capture |
GroupDragonfly | Dragonfly has performed screen captures of victims, including by using a tool, scr.exe (which matched the hash of ScreenUtil). |
| T1114.002 Remote Email Collection |
GroupDragonfly | Dragonfly has accessed email accounts using Outlook Web Access. |
| T1133 External Remote Services |
GroupDragonfly | Dragonfly has used VPNs and Outlook Web Access (OWA) to maintain access to victim networks. |
| T1135 Network Share Discovery |
GroupDragonfly | Dragonfly has identified and browsed file servers in the victim network, sometimes , viewing files pertaining to ICS or Supervisory Control and Data Acquisition (SCADA) systems. |
| T1136.001 Local Account |
GroupDragonfly | Dragonfly has created accounts on victims, including administrator accounts, some of which appeared to be tailored to each individual staging target. |
| T1187 Forced Authentication |
GroupDragonfly | Dragonfly has gathered hashed user credentials over SMB using spearphishing attachments with external resource links and by modifying .LNK file icon resources to collect credentials from virtualized systems. |
| T1189 Drive-by Compromise |
GroupDragonfly | Dragonfly has compromised targets via strategic web compromise (SWC) utilizing a custom exploit kit. |
| T1221 Template Injection |
GroupDragonfly | Dragonfly has injected SMB URLs into malicious Word spearphishing attachments to initiate Forced Authentication. |
| T1505.003 Web Shell |
GroupDragonfly | Dragonfly has commonly created Web shells on victims' publicly accessible email and web servers, which they used to maintain access to a victim network and download additional malicious files. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupDragonfly | Dragonfly has added the registry value ntdll to the Registry Run key to establish persistence. |
| T1560 Archive Collected Data |
GroupDragonfly | Dragonfly has compressed data into .zip files prior to exfiltration. |
| T1564.002 Hidden Users |
GroupDragonfly | Dragonfly has modified the Registry to hide created user accounts. |
| T1598.002 Spearphishing Attachment |
GroupDragonfly | Dragonfly has used spearphishing with Microsoft Office attachments to enable harvesting of user credentials. |
| T1598.003 Spearphishing Link |
GroupDragonfly | Dragonfly has used spearphishing with PDF attachments containing malicious links that redirected to credential harvesting websites. |
| T1685.005 Clear Windows Event Logs |
GroupDragonfly | Dragonfly has cleared Windows event logs and other logs produced by tools they used, including system, security, terminal services, remote services, and audit logs. The actors also deleted specific Registry keys. |
| T1686 Disable or Modify System Firewall |
GroupDragonfly | Dragonfly has disabled host-based firewalls. The group has also globally opened port 3389. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.