Vrabie, V. (2020, November). Dissecting a Chinese APT Targeting South Eastern Asian Government Institutions. Retrieved September 19, 2022.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1001 Data Obfuscation |
MalwareFunnyDream | FunnyDream can send compressed and obfuscated packets to C2. |
| T1005 Data from Local System |
Malwareccf32 | ccf32 can collect files from a compromised host. |
| T1005 Data from Local System |
ToolPcShare | PcShare can collect files and information from a compromised host. |
| T1005 Data from Local System |
MalwareFunnyDream | FunnyDream can upload files from victims' machines. |
| T1010 Application Window Discovery |
MalwareFunnyDream | FunnyDream has the ability to discover application windows via execution of `EnumWindows`. |
| T1012 Query Registry |
MalwareFunnyDream | FunnyDream can check `Software\Microsoft\Windows\CurrentVersion\Internet Settings` to extract the `ProxyServer` string. |
| T1012 Query Registry |
ToolPcShare | PcShare can search the registry files of a compromised host. |
| T1016 System Network Configuration Discovery |
MalwareFunnyDream | FunnyDream can parse the `ProxyServer` string in the Registry to discover http proxies. |
| T1016 System Network Configuration Discovery |
CampaignFunnyDream | During FunnyDream, the threat actors used ipconfig for discovery on remote systems. |
| T1016 System Network Configuration Discovery |
ToolPcShare | PcShare can obtain the proxy settings of a compromised machine using `InternetQueryOptionA` and its IP address by running `nslookup myip.opendns.comresolver1.opendns.com\r\n`. |
| T1018 Remote System Discovery |
CampaignFunnyDream | During FunnyDream, the threat actors used several tools and batch files to map victims' internal networks. |
| T1025 Data from Removable Media |
MalwareFunnyDream | The FunnyDream FilePakMonitor component has the ability to collect files from removable devices. |
| T1027.013 Encrypted/Encoded File |
MalwareFunnyDream | FunnyDream can Base64 encode its C2 address stored in a template binary with the `xyz0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvw_-` or |
| T1027.013 Encrypted/Encoded File |
ToolPcShare | PcShare has been encrypted with XOR using different 32-long Base16 strings. |
| T1027.013 Encrypted/Encoded File |
MalwareChinoxy | Chinoxy has encrypted its configuration file. |
| T1027.015 Compression |
ToolPcShare | PcShare has been compressed with LZW algorithm. |
| T1033 System Owner/User Discovery |
MalwareFunnyDream | FunnyDream has the ability to gather user information from the targeted system using `whoami/upn&whoami/fqdn&whoami/logonid&whoami/all`. |
| T1036.001 Invalid Code Signature |
ToolPcShare | PcShare has used an invalid certificate in attempt to appear legitimate. |
| T1036.004 Masquerade Task or Service |
MalwareFunnyDream | FunnyDream has used a service named `WSearch` for execution. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareChinoxy | Chinoxy has used the name `eoffice.exe` in attempt to appear as a legitimate file. |
| T1036.005 Match Legitimate Resource Name or Location |
ToolPcShare | PcShare has been named `wuauclt.exe` to appear as the legitimate Windows Update AutoUpdate Client. |
| T1041 Exfiltration Over C2 Channel |
ToolPcShare | PcShare can upload files and information from a compromised host to its C2 servers. |
| T1041 Exfiltration Over C2 Channel |
MalwareFunnyDream | FunnyDream can execute commands, including gathering user information, and send the results to C2. |
| T1047 Windows Management Instrumentation |
MalwareFunnyDream | FunnyDream can use WMI to open a Windows command shell on a remote machine. |
| T1047 Windows Management Instrumentation |
CampaignFunnyDream | During FunnyDream, the threat actors used `wmiexec.vbs` to run remote commands. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
Malwareccf32 | ccf32 can upload collected data and files to an FTP server. |
| T1049 System Network Connections Discovery |
CampaignFunnyDream | During FunnyDream, the threat actors used netstat to discover network connections on remote systems. |
| T1053.005 Scheduled Task |
Malwareccf32 | ccf32 can run on a daily basis using a scheduled task. |
| T1055 Process Injection |
ToolPcShare | The PcShare payload has been injected into the `logagent.exe` and `rdpclip.exe` processes. |
| T1055.001 Dynamic-link Library Injection |
MalwareFunnyDream | The FunnyDream FilepakMonitor component can inject into the Bka.exe process using the `VirtualAllocEx`, `WriteProcessMemory` and `CreateRemoteThread` APIs to load the DLL component. |
| T1056.001 Keylogging |
MalwareFunnyDream | The FunnyDream Keyrecord component can capture keystrokes. |
| T1056.001 Keylogging |
ToolPcShare | PcShare has the ability to capture keystrokes. |
| T1057 Process Discovery |
MalwareFunnyDream | FunnyDream has the ability to discover processes, including `Bka.exe` and `BkavUtil.exe`. |
| T1057 Process Discovery |
ToolPcShare | PcShare can obtain a list of running processes on a compromised host. |
| T1057 Process Discovery |
CampaignFunnyDream | During FunnyDream, the threat actors used Tasklist on targeted systems. |
| T1059.003 Windows Command Shell |
ToolPcShare | PcShare can execute `cmd` commands on a compromised host. |
| T1059.003 Windows Command Shell |
Malwareccf32 | ccf32 has used `cmd.exe` for archiving data and deleting files. |
| T1059.003 Windows Command Shell |
MalwareFunnyDream | FunnyDream can use `cmd.exe` for execution on remote hosts. |
| T1059.003 Windows Command Shell |
CampaignFunnyDream | During FunnyDream, the threat actors used `cmd.exe` to execute the wmiexec.vbs script. |
| T1059.005 Visual Basic |
CampaignFunnyDream | During FunnyDream, the threat actors used a Visual Basic script to run remote commands. |
| T1070 Indicator Removal |
MalwareFunnyDream | FunnyDream has the ability to clean traces of malware deployment. |
| T1070.004 File Deletion |
Malwareccf32 | ccf32 can delete files and folders from compromised machines. |
| T1070.004 File Deletion |
MalwareFunnyDream | FunnyDream can delete files including its dropper component. |
| T1070.004 File Deletion |
ToolPcShare | PcShare has deleted its files and components from a compromised host. |
| T1071.001 Web Protocols |
ToolPcShare | PcShare has used HTTP for C2 communication. |
| T1074.001 Local Data Staging |
MalwareFunnyDream | FunnyDream can stage collected information including screen captures and logged keystrokes locally. |
| T1074.001 Local Data Staging |
Malwareccf32 | ccf32 can temporarily store files in a hidden directory on the local host. |
| T1074.002 Remote Data Staging |
Malwareccf32 | ccf32 has copied files to a remote machine infected with Chinoxy or another backdoor. |
| T1082 System Information Discovery |
CampaignFunnyDream | During FunnyDream, the threat actors used Systeminfo to collect information on targeted hosts. |
| T1083 File and Directory Discovery |
MalwareFunnyDream | FunnyDream can identify files with .doc, .docx, .ppt, .pptx, .xls, .xlsx, and .pdf extensions and specific timestamps for collection. |
Showing the first 50.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.