ATT&CKReferencesTrendMicro EarthLusca 2022

TrendMicro EarthLusca 2022

Chen, J., et al. (2022). Delving Deep: An Analysis of Earth Lusca’s Operations. Retrieved July 1, 2022.

Open the source

Techniques1

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples47

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupEarth Lusca

Earth Lusca has used ProcDump to obtain the hashes of credentials by dumping the memory of the LSASS process.

T1003.006
DCSync
GroupEarth Lusca

Earth Lusca has used a DCSync command with Mimikatz to retrieve credentials from an exploited controller.

T1007
System Service Discovery
GroupEarth Lusca

Earth Lusca has used Tasklist to obtain information from a compromised host.

T1016
System Network Configuration Discovery
GroupEarth Lusca

Earth Lusca used the command ipconfig to obtain information about network configurations.

T1018
Remote System Discovery
GroupEarth Lusca

Earth Lusca used the command powershell “Get-EventLog -LogName security -Newest 500 | where {$_.EventID -eq 4624} | format-list -
property * | findstr “Address””
to find the network information of successfully logged-in accounts to discovery addresses of other machines. Earth Lusca has also used multiple scanning tools to discover other machines within the same compromised network.

T1027
Obfuscated Files or Information
GroupEarth Lusca

Earth Lusca used Base64 to encode strings.

T1027
Obfuscated Files or Information
MalwareShadowPad

ShadowPad has encrypted its payload, a virtual file system, and various files.

T1027.003
Steganography
GroupEarth Lusca

Earth Lusca has used steganography to hide shellcode in a BMP image file.

T1027.011
Fileless Storage
MalwareShadowPad

ShadowPad maintains a configuration block and virtual file system in the Registry.

T1033
System Owner/User Discovery
GroupEarth Lusca

Earth Lusca collected information on user accounts via the whoami command.

T1036.005
Match Legitimate Resource Name or Location
GroupEarth Lusca

Earth Lusca used the command `move [file path] c:\windows\system32\spool\prtprocs\x64\spool.dll` to move and register a malicious DLL name as a Windows print processor, which eventually was loaded by the Print Spooler service.

T1047
Windows Management Instrumentation
GroupEarth Lusca

Earth Lusca used a VBA script to execute WMI.

T1049
System Network Connections Discovery
GroupEarth Lusca

Earth Lusca employed a PowerShell script called RDPConnectionParser to read and filter the Windows event log “Microsoft-Windows-TerminalServices-RDPClient/Operational”
(Event ID 1024) to obtain network information from RDP connections. Earth Lusca has also used netstat from a compromised system to obtain network connection information.

T1053.005
Scheduled Task
GroupEarth Lusca

Earth Lusca used the command schtasks /Create /SC ONLOgon /TN WindowsUpdateCheck /TR “[file path]” /ru system for persistence.

T1057
Process Discovery
GroupEarth Lusca

Earth Lusca has used Tasklist to obtain information from a compromised host.

T1059.001
PowerShell
GroupEarth Lusca

Earth Lusca has used PowerShell to execute commands.

T1059.005
Visual Basic
GroupEarth Lusca

Earth Lusca used VBA scripts.

T1059.006
Python
GroupEarth Lusca

Earth Lusca used Python scripts for port scanning or building reverse shells.

T1059.007
JavaScript
GroupEarth Lusca

Earth Lusca has manipulated legitimate websites to inject malicious JavaScript code as part of their watering hole operations.

T1090
Proxy
GroupEarth Lusca

Earth Lusca adopted Cloudflare as a proxy for compromised servers.

T1098.004
SSH Authorized Keys
GroupEarth Lusca

Earth Lusca has dropped an SSH-authorized key in the `/root/.ssh` folder in order to access a compromised server with SSH.

T1112
Modify Registry
GroupEarth Lusca

Earth Lusca modified the registry using the command reg add “HKEY_CURRENT_USER\Environment” /v UserInitMprLogonScript /t REG_SZ /d “[file path]” for persistence.

T1112
Modify Registry
MalwareShadowPad

ShadowPad can modify the Registry to store and maintain a configuration block and virtual file system.

T1140
Deobfuscate/Decode Files or Information
GroupEarth Lusca

Earth Lusca has used certutil to decode a string into a cabinet file.

T1189
Drive-by Compromise
GroupEarth Lusca

Earth Lusca has performed watering hole attacks.

T1190
Exploit Public-Facing Application
GroupEarth Lusca

Earth Lusca has compromised victims by directly exploiting vulnerabilities of public-facing servers, including those associated with Microsoft Exchange and Oracle GlassFish.

T1204.001
Malicious Link
GroupEarth Lusca

Earth Lusca has sent spearphishing emails that required the user to click on a malicious link and subsequently open a decoy document with a malicious loader.

T1204.002
Malicious File
GroupEarth Lusca

Earth Lusca required users to click on a malicious file for the loader to activate.

T1210
Exploitation of Remote Services
GroupEarth Lusca

Earth Lusca has used Mimikatz to exploit a domain controller via the ZeroLogon exploit (CVE-2020-1472).

T1218.005
Mshta
GroupEarth Lusca

Earth Lusca has used `mshta.exe` to load an HTA script within a malicious .LNK file.

T1482
Domain Trust Discovery
GroupEarth Lusca

Earth Lusca has used Nltest to obtain information about domain controllers.

T1543.003
Windows Service
GroupEarth Lusca

Earth Lusca created a service using the command sc create “SysUpdate” binpath= “cmd /c start “[file path]””&&sc config “SysUpdate” start= auto&&net
start SysUpdate
for persistence.

T1547.012
Print Processors
GroupEarth Lusca

Earth Lusca has added the Registry key `HKLM\SYSTEM\ControlSet001\Control\Print\Environments\Windows x64\Print Processors\UDPrint” /v Driver /d “spool.dll /f` to load malware as a Print Processor.

T1548.002
Bypass User Account Control
GroupEarth Lusca

Earth Lusca has used the Fodhelper UAC bypass technique to gain elevated privileges.

T1560.001
Archive via Utility
GroupEarth Lusca

Earth Lusca has used WinRAR to compress stolen files into an archive prior to exfiltration.

T1566.002
Spearphishing Link
GroupEarth Lusca

Earth Lusca has sent spearphishing emails to potential targets that contained a malicious link.

T1567.002
Exfiltration to Cloud Storage
GroupEarth Lusca

Earth Lusca has used the megacmd tool to upload stolen files from a victim network to MEGA.

T1574.001
DLL
GroupEarth Lusca

Earth Lusca has placed a malicious payload in `%WINDIR%\SYSTEM32\oci.dll` so it would be sideloaded by the MSDTC service.

T1583.001
Domains
GroupEarth Lusca

Earth Lusca has registered domains, intended to look like legitimate target domains, that have been used in watering hole attacks.

T1583.004
Server
GroupEarth Lusca

Earth Lusca has acquired multiple servers for some of their operations, using each server for a different role.

T1583.006
Web Services
GroupEarth Lusca

Earth Lusca has established GitHub accounts to host their malware.

T1584.004
Server
GroupEarth Lusca

Earth Lusca has used compromised web servers as part of their operational infrastructure.

T1584.006
Web Services
GroupEarth Lusca

Earth Lusca has compromised Google Drive repositories.

T1588.001
Malware
GroupEarth Lusca

Earth Lusca has acquired and used a variety of malware, including Cobalt Strike.

T1588.002
Tool
GroupEarth Lusca

Earth Lusca has acquired and used a variety of open source tools.

T1595.002
Vulnerability Scanning
GroupEarth Lusca

Earth Lusca has scanned for vulnerabilities in the public-facing servers of their targets.

T1608.001
Upload Malware
GroupEarth Lusca

Earth Lusca has staged malware and malicious files on compromised web servers, GitHub, and Google Drive.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.