ATT&CKReferencesESET Okrum July 2019

ESET Okrum July 2019

Hromcova, Z. (2019, July). OKRUM AND KETRICAN: AN OVERVIEW OF RECENT KE3CHANG GROUP ACTIVITY. Retrieved May 6, 2020.

Open the source

Techniques1

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples34

TechniqueUsed byProcedure example
T1001
Data Obfuscation
MalwareOkrum

Okrum leverages the HTTP protocol for C2 communication, while hiding the actual messages in the Cookie and Set-Cookie headers of the HTTP requests.

T1001.003
Protocol or Service Impersonation
MalwareOkrum

Okrum leverages the HTTP protocol for C2 communication, while hiding the actual messages in the Cookie and Set-Cookie headers of the HTTP requests.

T1003.001
LSASS Memory
MalwareOkrum

Okrum was seen using MimikatzLite to perform credential dumping.

T1003.005
Cached Domain Credentials
MalwareOkrum

Okrum was seen using modified Quarks PwDump to perform credential dumping.

T1016
System Network Configuration Discovery
MalwareOkrum

Okrum can collect network information, including the host IP address, DNS, and proxy information.

T1027.003
Steganography
MalwareOkrum

Okrum's payload is encrypted and embedded within its loader, or within a legitimate PNG file.

T1033
System Owner/User Discovery
MalwareOkrum

Okrum can collect the victim username.

T1036.004
Masquerade Task or Service
MalwareOkrum

Okrum can establish persistence by adding a new service NtmsSvc with the display name Removable Storage to masquerade as a legitimate Removable Storage Manager.

T1041
Exfiltration Over C2 Channel
MalwareOkrum

Data exfiltration is done by Okrum using the already opened channel with the C2 server.

T1049
System Network Connections Discovery
MalwareOkrum

Okrum was seen using NetSess to discover NetBIOS sessions.

T1053.005
Scheduled Task
MalwareOkrum

Okrum's installer can attempt to achieve persistence by creating a scheduled task.

T1056.001
Keylogging
MalwareOkrum

Okrum was seen using a keylogger tool to capture keystrokes.

T1059.003
Windows Command Shell
MalwareOkrum

Okrum's backdoor has used cmd.exe to execute arbitrary commands as well as batch scripts to update itself to a newer version.

T1070.004
File Deletion
MalwareOkrum

Okrum's backdoor deletes files after they have been successfully uploaded to C2 servers.

T1071.001
Web Protocols
MalwareOkrum

Okrum uses HTTP for communication with its C2.

T1082
System Information Discovery
MalwareOkrum

Okrum can collect computer name, locale information, and information about the OS and architecture.

T1083
File and Directory Discovery
MalwareOkrum

Okrum has used DriveLetterView to enumerate drive information.

T1090.002
External Proxy
MalwareOkrum

Okrum can identify proxy servers configured and used by the victim, and use it to make HTTP requests to C2 its server.

T1105
Ingress Tool Transfer
MalwareOkrum

Okrum has built-in commands for uploading, downloading, and executing files to the system.

T1124
System Time Discovery
MalwareOkrum

Okrum can obtain the date and time of the compromised system.

T1132.001
Standard Encoding
MalwareOkrum

Okrum has used base64 to encode C2 communication.

T1134.001
Token Impersonation/Theft
MalwareOkrum

Okrum can impersonate a logged-on user's security context using a call to the ImpersonateLoggedOnUser API.

T1140
Deobfuscate/Decode Files or Information
MalwareOkrum

Okrum's loader can decrypt the backdoor code, embedded within the loader or within a legitimate PNG file. A custom XOR cipher or RC4 is used for decryption.

T1497.001
System Checks
MalwareOkrum

Okrum's loader can check the amount of physical memory and terminates itself if the host has less than 1.5 Gigabytes of physical memory in total.

T1497.002
User Activity Based Checks
MalwareOkrum

Okrum loader only executes the payload after the left mouse button has been pressed at least three times, in order to avoid being executed within virtualized or emulated environments.

T1497.003
Time Based Checks
MalwareOkrum

Okrum's loader can detect presence of an emulator by using two calls to GetTickCount API, and checking whether the time has been accelerated.

T1543.003
Windows Service
MalwareOkrum

To establish persistence, Okrum can install itself as a new service named NtmSsvc.

T1547.001
Registry Run Keys / Startup Folder
MalwareOkrum

Okrum establishes persistence by creating a .lnk shortcut to itself in the Startup folder.

T1547.009
Shortcut Modification
MalwareOkrum

Okrum can establish persistence by creating a .lnk shortcut to itself in the Startup folder.

T1560.001
Archive via Utility
MalwareOkrum

Okrum was seen using a RAR archiver tool to compress/decompress data.

T1560.003
Archive via Custom Method
MalwareOkrum

Okrum has used a custom implementation of AES encryption to encrypt collected data.

T1564.001
Hidden Files and Directories
MalwareOkrum

Before exfiltration, Okrum's backdoor has used hidden files to store logs and outputs from backdoor commands.

T1569.002
Service Execution
MalwareOkrum

Okrum's loader can create a new service named NtmsSvc to execute the payload.

T1573.001
Symmetric Cryptography
MalwareOkrum

Okrum uses AES to encrypt network traffic. The key can be hardcoded or negotiated with the C2 server in the registration phase.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.