Punsaen Boonyakarn, Shawn Chew, Logeswaran Nadarajan, Mathew Potaczek, Jakub Jozwiak, and Alex Marvi. (2024, June 18). Cloaked and Covert: Uncovering UNC3886 Espionage Operations. Retrieved September 24, 2024.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1008 Fallback Channels |
GroupUNC3886 | UNC3886 has employed layers of redundancy to maintain access to compromised environments including network devices, hypervisors, and virtual machines. |
| T1014 Rootkit |
MalwareREPTILE | REPTILE has the ability to hook kernel functions and modify functions data to achieve rootkit functionality such as hiding processes and network connections. |
| T1014 Rootkit |
GroupUNC3886 | UNC3886 has used the publicly available rootkits REPTILE and MEDUSA on targeted VMs. |
| T1014 Rootkit |
MalwareMEDUSA | MEDUSA is a rootkit with command execution and credential logging capabilities. |
| T1027.013 Encrypted/Encoded File |
MalwareMOPSLED | MOPSLED can encrypt configuration files with a custom ChaCha20 algorithm. |
| T1027.013 Encrypted/Encoded File |
MalwareMEDUSA | MEDUSA can XOR encrypt configuration strings. |
| T1040 Network Sniffing |
GroupUNC3886 | UNC3886 has used the LOOKOVER sniffer to sniff TACACS+ authentication packets. |
| T1059.004 Unix Shell |
MalwareREPTILE | REPTILE can deploy components automatically with shell scripts. |
| T1059.004 Unix Shell |
MalwareRIFLESPINE | RIFLESPINE can execute commands with `/bin/sh`. |
| T1059.006 Python |
MalwareVIRTUALPIE | VIRTUALPIE is a Python-based backdoor malware. |
| T1071.001 Web Protocols |
MalwareMOPSLED | MOPSLED can communicate to C2 nodes over HTTP. |
| T1071.001 Web Protocols |
MalwareRIFLESPINE | RIFLESPINE can use HTTP `GET` and `PUT` to upload and download files. |
| T1074.001 Local Data Staging |
GroupUNC3886 | UNC3886 has staged captured credentials in `var/log/ldapd<unique_keyword>.2.gz`. |
| T1074.001 Local Data Staging |
MalwareRIFLESPINE | RIFLESPINE can stage the output from executed C2 commands to a temporary file. |
| T1078 Valid Accounts |
GroupUNC3886 | UNC3886 has used tools to hijack valid SSH accounts. |
| T1082 System Information Discovery |
MalwareRIFLESPINE | RIFLESPINE can collect system information after installation on infected systems. |
| T1095 Non-Application Layer Protocol |
MalwareMOPSLED | MOPSLED can use a custom binary protocol over TCP for C2 communication. |
| T1095 Non-Application Layer Protocol |
MalwareREPTILE | REPTILE can communicate using TLS over raw TCP. |
| T1095 Non-Application Layer Protocol |
GroupUNC3886 | UNC3886 has deployed backdoors that communicate over TCP to compromised network devices and over VMCI to ESXi hosts. |
| T1102 Web Service |
MalwareMOPSLED | MOPSLED can use third-party web services such as GitHub and Google Drive for C2. |
| T1102.001 Dead Drop Resolver |
MalwareMOPSLED | MOPSLED has the ability to retrieve a C2 address from a dead drop URL. |
| T1102.002 Bidirectional Communication |
MalwareRIFLESPINE | RIFLESPINE can retrieve C2 commands from an encrypted file on Google Drive then upload the results of command execution back to Google Drive. |
| T1105 Ingress Tool Transfer |
MalwareRIFLESPINE | RIFLESPINE can download and execute files. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareREPTILE | The REPTILE launcher component can decrypt kernel module code from a file and load it into memory. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareRIFLESPINE | RIFLESPINE can deobfuscate encrypted files prior to execution on targeted hosts. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareMOPSLED | MOPSLED can decrypt obfuscated configuration files. |
| T1190 Exploit Public-Facing Application |
GroupUNC3886 | UNC3886 has exploited CVE-2022-42475 in FortiOS SSL VPNs to obtain access. |
| T1203 Exploitation for Client Execution |
GroupUNC3886 | UNC3886 has exoloited CVE-2023-34048 to enable command execution on vCenter servers and CVE-2023-20867 in VMware Tools to execute unauthenticated Guest Operations from ESXi hosts to guest VMs. |
| T1205 Traffic Signaling |
MalwareREPTILE | The REPTILE reverse shell component can listen for a specialized packet in TCP, UDP, or ICMP for activation. |
| T1205.001 Port Knocking |
MalwareREPTILE | REPTILE has the ability to control compromised endpoints via port knocking. |
| T1212 Exploitation for Credential Access |
GroupUNC3886 | UNC3886 exploited CVE-2022-22948 in VMware vCenter to obtain encrypted credentials from the vCenter postgresDB. |
| T1543.002 Systemd Service |
MalwareRIFLESPINE | RIFLESPINE can create a systemd service file for execution. |
| T1543.004 Launch Daemon |
MalwareREPTILE | The REPTILE launcher can daemonize a process. |
| T1546.017 Udev Rules |
MalwareREPTILE | REPTILE has used udev for persistence. |
| T1547.006 Kernel Modules and Extensions |
MalwareREPTILE | The REPTILE rootkit is implemented as a loadable kernel module (LKM). |
| T1554 Compromise Host Software Binary |
GroupUNC3886 | UNC3886 has trojanized Fortinet firmware and replaced the legitimate `/usr/bin/tac_plus` TACACS+ daemon for Linux with a malicious version containing credential logging functionality. |
| T1560.001 Archive via Utility |
GroupUNC3886 | UNC3886 has used Gzip and the Windows command `makecab` to compress files and stolen credentials from victim systems. |
| T1560.003 Archive via Custom Method |
GroupUNC3886 | UNC3886 has XOR encrypted and Gzip compressed captured credentials. |
| T1563.001 SSH Hijacking |
MalwareMEDUSA | MEDUSA can be configured to capture SSH credentials via SSH hijacking. |
| T1564.001 Hidden Files and Directories |
MalwareREPTILE | REPTILE has the ability to communicate with the kernel-mode component to hide files. |
| T1567.002 Exfiltration to Cloud Storage |
MalwareRIFLESPINE | RIFLESPINE can upload results from executed C2 commands to cloud storage. |
| T1573.001 Symmetric Cryptography |
MalwareVIRTUALPIE | VIRTUALPIE can use a custom RC4 encrypted protocol for C2 communications. |
| T1573.001 Symmetric Cryptography |
MalwareRIFLESPINE | RIFLESPINE can use the AES algorithm to encrypt C2 data. |
| T1573.002 Asymmetric Cryptography |
MalwareREPTILE | REPTILE can use TLS over raw TCP for secure C2. |
| T1574.006 Dynamic Linker Hijacking |
MalwareMEDUSA | MEDUSA can execute code through dynamic linker hijacking of the `LD_PRELOAD` library. |
| T1587.004 Exploits |
GroupUNC3886 | UNC3886 has used zero-day vulnerabilities CVE-2022-41328 against FortiOS and CVE-2023-20867 and CVE-2023-34048 against VMware vCenter. |
| T1588.001 Malware |
GroupUNC3886 | UNC3886 has used the publicly available rootkits REPTILE and MEDUSA. |
| T1588.004 Digital Certificates |
GroupUNC3886 | UNC3886 has deployed malware using the victim's legitimate TLS certificate obtained from a compromised FortiGate device. |
| T1675 ESXi Administration Command |
GroupUNC3886 | UNC3886 used `vmtoolsd.exe` to run commands on guest virtual machines from a compromised ESXi host. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.