SEONGSU PARK. (2022, December 27). BlueNoroff introduces new methods bypassing MoTW. Retrieved February 6, 2024.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1036.003 Rename Legitimate Utilities |
GroupAPT38 | APT38 has renamed system utilities, such as `rundll32.exe` and `mshta.exe`, to avoid detection. |
| T1036.006 Space after Filename |
GroupAPT38 | APT38 has put several spaces before a file extension to avoid detection and suspicion. |
| T1053.005 Scheduled Task |
GroupAPT38 | APT38 has used Task Scheduler to run programs at system startup or on a scheduled basis for persistence. Additionally, APT38 has used living-off-the-land scripts to execute a malicious script via a scheduled task. |
| T1055 Process Injection |
GroupAPT38 | APT38 has injected malicious payloads into the `explorer.exe` process. |
| T1059.003 Windows Command Shell |
GroupAPT38 | APT38 has used a command-line tunneler, NACHOCHEESE, to give them shell access to a victim’s machine. Additionally, APT38 has used batch scripts. |
| T1059.005 Visual Basic |
GroupAPT38 | APT38 has used VBScript to execute commands and other operational tasks. |
| T1105 Ingress Tool Transfer |
GroupAPT38 | APT38 used a backdoor, NESTEGG, that has the capability to download and upload files to and from a victim’s machine. Additionally, APT38 has downloaded other payloads onto a victim’s machine. |
| T1140 Deobfuscate/Decode Files or Information |
GroupAPT38 | APT38 has used the RC4 algorithm to decrypt configuration data. |
| T1204.001 Malicious Link |
GroupAPT38 | APT38 has used links to execute a malicious Visual Basic script. |
| T1204.002 Malicious File |
GroupAPT38 | APT38 has attempted to lure victims into enabling malicious macros within email attachments. Additionally, APT38 has used malicious Word documents and shortcut files. |
| T1218.005 Mshta |
GroupAPT38 | APT38 has used a renamed version of `mshta.exe` to execute malicious HTML files. |
| T1218.007 Msiexec |
GroupAPT38 | APT38 has used `msiexec.exe` to execute malicious files. |
| T1218.011 Rundll32 |
GroupAPT38 | APT38 has used rundll32.exe to execute binaries, scripts, and Control Panel Item files and to execute code via proxy to avoid triggering security tools. |
| T1480.002 Mutual Exclusion |
GroupAPT38 | APT38 has created a mutex to avoid duplicate execution. |
| T1518.001 Security Software Discovery |
GroupAPT38 | APT38 has identified security software, configurations, defensive tools, and sensors installed on a compromised system. |
| T1548.002 Bypass User Account Control |
GroupAPT38 | APT38 has used the legitimate application `ieinstal.exe` to bypass UAC. |
| T1553.005 Mark-of-the-Web Bypass |
GroupAPT38 | APT38 has used ISO and VHD files to deploy malware and to bypass Mark-of-the-Web (MOTW) security measures. |
| T1583.001 Domains |
GroupAPT38 | APT38 has created fake domains to imitate legitimate venture capital or bank domains. |
| T1685 Disable or Modify Tools |
GroupAPT38 | APT38 has unhooked DLLs to disable endpoint detection and response (EDR) or anti-virus (AV) tools. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.