ATT&CKReferencesSygnia Elephant Beetle Jan 2022

Sygnia Elephant Beetle Jan 2022

Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

Open the source

Techniques1

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples35

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupFIN13

FIN13 has obtained memory dumps with ProcDump to parse and extract credentials from a victim's LSASS process memory with Mimikatz.

T1003.002
Security Account Manager
GroupFIN13

FIN13 has extracted the SAM and SYSTEM registry hives using the `reg.exe` binary for obtaining password hashes from a compromised machine.

T1003.003
NTDS
GroupFIN13

FIN13 has harvested the NTDS.DIT file and leveraged the Impacket tool on the compromised domain controller to locally decrypt it.

T1005
Data from Local System
GroupFIN13

FIN13 has gathered stolen credentials, sensitive data such as point-of-sale (POS), and ATM data from a compromised network before exfiltration.

T1016
System Network Configuration Discovery
GroupFIN13

FIN13 has used `nslookup` and `ipconfig` for network reconnaissance efforts. FIN13 has also utilized a compromised Symantec Altiris console and LanDesk account to retrieve network information.

T1021.002
SMB/Windows Admin Shares
GroupFIN13

FIN13 has leveraged SMB to move laterally within a compromised network via application servers and SQL servers.

T1021.006
Windows Remote Management
GroupFIN13

FIN13 has leveraged `WMI` to move laterally within a compromised network via application servers and SQL servers.

T1036
Masquerading
GroupFIN13

FIN13 has masqueraded staged data by using the Windows certutil utility to generate fake Base64 encoded certificates with the input file.

T1036.005
Match Legitimate Resource Name or Location
GroupFIN13

FIN13 has masqueraded WAR files to look like legitimate packages such as, wsexample.war, wsexamples.com, examples.war, and exampl3s.war.

T1046
Network Service Discovery
GroupFIN13

FIN13 has utilized `nmap` for reconnaissance efforts. FIN13 has also scanned for internal MS-SQL servers in a compromised network.

T1047
Windows Management Instrumentation
GroupFIN13

FIN13 has utilized `WMI` to execute commands and move laterally on compromised Windows machines.

T1059.003
Windows Command Shell
GroupFIN13

FIN13 has leveraged `xp_cmdshell` and Windows Command Shell to execute commands on a compromised machine. FIN13 has also attempted to leverage the ‘xp_cmdshell’ SQL procedure to execute remote commands on internal MS-SQL servers.

T1059.005
Visual Basic
GroupFIN13

FIN13 has used VBS scripts for code execution on comrpomised machines.

T1071.001
Web Protocols
GroupFIN13

FIN13 has used HTTP requests to chain multiple web shells and to contact actor-controlled C2 servers prior to exfiltrating stolen data.

T1074.001
Local Data Staging
GroupFIN13

FIN13 has utilized the following temporary folders on compromised Windows and Linux systems for their operations prior to exfiltration: `C:\Windows\Temp` and `/tmp`.

T1078.001
Default Accounts
GroupFIN13

FIN13 has leveraged default credentials for authenticating myWebMethods (WMS) and QLogic web management interface to gain initial access.

T1082
System Information Discovery
GroupFIN13

FIN13 has collected local host information by utilizing Windows commands `systeminfo`, `fsutil`, and `fsinfo`. FIN13 has also utilized a compromised Symantex Altiris console and LanDesk account to retrieve host information.

T1087.002
Domain Account
GroupFIN13

FIN13 can identify user accounts associated with a Service Principal Name and query Service Principal Names within the domain by utilizing the following scripts: `GetUserSPNs.vbs` and `querySpn.vbs`.

T1090.001
Internal Proxy
GroupFIN13

FIN13 has utilized a proxy tool to communicate between compromised assets.

T1098.007
Additional Local or Domain Groups
GroupFIN13

FIN13 has assigned newly created accounts the sysadmin role to maintain persistence.

T1105
Ingress Tool Transfer
GroupFIN13

FIN13 has downloaded additional tools and malware to compromised systems.

T1134.003
Make and Impersonate Token
GroupFIN13

FIN13 has utilized tools such as Incognito V2 for token manipulation and impersonation.

T1135
Network Share Discovery
GroupFIN13

FIN13 has executed net view commands for enumeration of open shares on compromised machines.

T1136.001
Local Account
GroupFIN13

FIN13 has created MS-SQL local accounts in a compromised network.

T1190
Exploit Public-Facing Application
GroupFIN13

FIN13 has exploited known vulnerabilities such as CVE-2017-1000486 (Primefaces Application Expression Language Injection), CVE-2015-7450 (WebSphere Application Server SOAP Deserialization Exploit), CVE-2010-5326 (SAP NewWeaver Invoker Servlet Exploit), and EDB-ID-24963 (SAP NetWeaver ConfigServlet Remote Code Execution) to gain initial access.

T1505.003
Web Shell
GroupFIN13

FIN13 has utilized obfuscated and open-source web shells such as JspSpy, reGeorg, MiniWebCmdShell, and Vonloesch Jsp File Browser 1.2 to enable remote code execution and to execute commands on compromised web server.

T1552.001
Credentials In Files
GroupFIN13

FIN13 has obtained administrative credentials by browsing through local files on a compromised machine.

T1560.001
Archive via Utility
GroupFIN13

FIN13 has compressed the dump output of compromised credentials with a 7zip binary.

T1564.001
Hidden Files and Directories
GroupFIN13

FIN13 has created hidden files and folders within a compromised Linux system `/tmp` directory. FIN13 also has used `attrib.exe` to hide gathered local host information.

T1565
Data Manipulation
GroupFIN13

FIN13 has injected fraudulent transactions into compromised networks that mimic legitimate behavior to siphon off incremental amounts of money.

T1572
Protocol Tunneling
GroupFIN13

FIN13 has utilized web shells and Java tools for tunneling capabilities to and from compromised assets.

T1574.001
DLL
GroupFIN13

FIN13 has used IISCrack.dll as a side-loading technique to load a malicious version of httpodbc.dll on old IIS Servers (CVE-2001-0507).

T1587.001
Malware
GroupFIN13

FIN13 has utilized custom malware to maintain persistence in a compromised environment.

T1588.002
Tool
GroupFIN13

FIN13 has utilized publicly available tools such as Mimikatz, Impacket, PWdump7, ProcDump, Nmap, and Incognito V2 for targeting efforts.

T1657
Financial Theft
GroupFIN13

FIN13 has observed the victim's software and infrastructure over several months to understand the technical process of legitimate financial transactions, prior to attempting to conduct fraudulent transactions.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.