ATT&CKReferencesBitdefender FunnyDream Campaign November 2020

Bitdefender FunnyDream Campaign November 2020

Vrabie, V. (2020, November). Dissecting a Chinese APT Targeting South Eastern Asian Government Institutions. Retrieved September 19, 2022.

Open the source

Techniques1

Groups0

None recorded.

Software4

Campaigns1

Procedure examples88

TechniqueUsed byProcedure example
T1001
Data Obfuscation
MalwareFunnyDream

FunnyDream can send compressed and obfuscated packets to C2.

T1005
Data from Local System
Malwareccf32

ccf32 can collect files from a compromised host.

T1005
Data from Local System
ToolPcShare

PcShare can collect files and information from a compromised host.

T1005
Data from Local System
MalwareFunnyDream

FunnyDream can upload files from victims' machines.

T1010
Application Window Discovery
MalwareFunnyDream

FunnyDream has the ability to discover application windows via execution of `EnumWindows`.

T1012
Query Registry
MalwareFunnyDream

FunnyDream can check `Software\Microsoft\Windows\CurrentVersion\Internet Settings` to extract the `ProxyServer` string.

T1012
Query Registry
ToolPcShare

PcShare can search the registry files of a compromised host.

T1016
System Network Configuration Discovery
MalwareFunnyDream

FunnyDream can parse the `ProxyServer` string in the Registry to discover http proxies.

T1016
System Network Configuration Discovery
CampaignFunnyDream

During FunnyDream, the threat actors used ipconfig for discovery on remote systems.

T1016
System Network Configuration Discovery
ToolPcShare

PcShare can obtain the proxy settings of a compromised machine using `InternetQueryOptionA` and its IP address by running `nslookup myip.opendns.comresolver1.opendns.com\r\n`.

T1018
Remote System Discovery
CampaignFunnyDream

During FunnyDream, the threat actors used several tools and batch files to map victims' internal networks.

T1025
Data from Removable Media
MalwareFunnyDream

The FunnyDream FilePakMonitor component has the ability to collect files from removable devices.

T1027.013
Encrypted/Encoded File
MalwareFunnyDream

FunnyDream can Base64 encode its C2 address stored in a template binary with the `xyz0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvw_-` or
`xyz0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvw_=` character sets.

T1027.013
Encrypted/Encoded File
ToolPcShare

PcShare has been encrypted with XOR using different 32-long Base16 strings.

T1027.013
Encrypted/Encoded File
MalwareChinoxy

Chinoxy has encrypted its configuration file.

T1027.015
Compression
ToolPcShare

PcShare has been compressed with LZW algorithm.

T1033
System Owner/User Discovery
MalwareFunnyDream

FunnyDream has the ability to gather user information from the targeted system using `whoami/upn&whoami/fqdn&whoami/logonid&whoami/all`.

T1036.001
Invalid Code Signature
ToolPcShare

PcShare has used an invalid certificate in attempt to appear legitimate.

T1036.004
Masquerade Task or Service
MalwareFunnyDream

FunnyDream has used a service named `WSearch` for execution.

T1036.005
Match Legitimate Resource Name or Location
MalwareChinoxy

Chinoxy has used the name `eoffice.exe` in attempt to appear as a legitimate file.

T1036.005
Match Legitimate Resource Name or Location
ToolPcShare

PcShare has been named `wuauclt.exe` to appear as the legitimate Windows Update AutoUpdate Client.

T1041
Exfiltration Over C2 Channel
ToolPcShare

PcShare can upload files and information from a compromised host to its C2 servers.

T1041
Exfiltration Over C2 Channel
MalwareFunnyDream

FunnyDream can execute commands, including gathering user information, and send the results to C2.

T1047
Windows Management Instrumentation
MalwareFunnyDream

FunnyDream can use WMI to open a Windows command shell on a remote machine.

T1047
Windows Management Instrumentation
CampaignFunnyDream

During FunnyDream, the threat actors used `wmiexec.vbs` to run remote commands.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
Malwareccf32

ccf32 can upload collected data and files to an FTP server.

T1049
System Network Connections Discovery
CampaignFunnyDream

During FunnyDream, the threat actors used netstat to discover network connections on remote systems.

T1053.005
Scheduled Task
Malwareccf32

ccf32 can run on a daily basis using a scheduled task.

T1055
Process Injection
ToolPcShare

The PcShare payload has been injected into the `logagent.exe` and `rdpclip.exe` processes.

T1055.001
Dynamic-link Library Injection
MalwareFunnyDream

The FunnyDream FilepakMonitor component can inject into the Bka.exe process using the `VirtualAllocEx`, `WriteProcessMemory` and `CreateRemoteThread` APIs to load the DLL component.

T1056.001
Keylogging
MalwareFunnyDream

The FunnyDream Keyrecord component can capture keystrokes.

T1056.001
Keylogging
ToolPcShare

PcShare has the ability to capture keystrokes.

T1057
Process Discovery
MalwareFunnyDream

FunnyDream has the ability to discover processes, including `Bka.exe` and `BkavUtil.exe`.

T1057
Process Discovery
ToolPcShare

PcShare can obtain a list of running processes on a compromised host.

T1057
Process Discovery
CampaignFunnyDream

During FunnyDream, the threat actors used Tasklist on targeted systems.

T1059.003
Windows Command Shell
ToolPcShare

PcShare can execute `cmd` commands on a compromised host.

T1059.003
Windows Command Shell
Malwareccf32

ccf32 has used `cmd.exe` for archiving data and deleting files.

T1059.003
Windows Command Shell
MalwareFunnyDream

FunnyDream can use `cmd.exe` for execution on remote hosts.

T1059.003
Windows Command Shell
CampaignFunnyDream

During FunnyDream, the threat actors used `cmd.exe` to execute the wmiexec.vbs script.

T1059.005
Visual Basic
CampaignFunnyDream

During FunnyDream, the threat actors used a Visual Basic script to run remote commands.

T1070
Indicator Removal
MalwareFunnyDream

FunnyDream has the ability to clean traces of malware deployment.

T1070.004
File Deletion
Malwareccf32

ccf32 can delete files and folders from compromised machines.

T1070.004
File Deletion
MalwareFunnyDream

FunnyDream can delete files including its dropper component.

T1070.004
File Deletion
ToolPcShare

PcShare has deleted its files and components from a compromised host.

T1071.001
Web Protocols
ToolPcShare

PcShare has used HTTP for C2 communication.

T1074.001
Local Data Staging
MalwareFunnyDream

FunnyDream can stage collected information including screen captures and logged keystrokes locally.

T1074.001
Local Data Staging
Malwareccf32

ccf32 can temporarily store files in a hidden directory on the local host.

T1074.002
Remote Data Staging
Malwareccf32

ccf32 has copied files to a remote machine infected with Chinoxy or another backdoor.

T1082
System Information Discovery
CampaignFunnyDream

During FunnyDream, the threat actors used Systeminfo to collect information on targeted hosts.

T1083
File and Directory Discovery
MalwareFunnyDream

FunnyDream can identify files with .doc, .docx, .ppt, .pptx, .xls, .xlsx, and .pdf extensions and specific timestamps for collection.

Showing the first 50.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.