1 - appv

SEONGSU PARK. (2022, December 27). BlueNoroff introduces new methods bypassing MoTW. Retrieved February 6, 2024.

Open the source

Techniques1

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples19

TechniqueUsed byProcedure example
T1036.003
Rename Legitimate Utilities
GroupAPT38

APT38 has renamed system utilities, such as `rundll32.exe` and `mshta.exe`, to avoid detection.

T1036.006
Space after Filename
GroupAPT38

APT38 has put several spaces before a file extension to avoid detection and suspicion.

T1053.005
Scheduled Task
GroupAPT38

APT38 has used Task Scheduler to run programs at system startup or on a scheduled basis for persistence. Additionally, APT38 has used living-off-the-land scripts to execute a malicious script via a scheduled task.

T1055
Process Injection
GroupAPT38

APT38 has injected malicious payloads into the `explorer.exe` process.

T1059.003
Windows Command Shell
GroupAPT38

APT38 has used a command-line tunneler, NACHOCHEESE, to give them shell access to a victim’s machine. Additionally, APT38 has used batch scripts.

T1059.005
Visual Basic
GroupAPT38

APT38 has used VBScript to execute commands and other operational tasks.

T1105
Ingress Tool Transfer
GroupAPT38

APT38 used a backdoor, NESTEGG, that has the capability to download and upload files to and from a victim’s machine. Additionally, APT38 has downloaded other payloads onto a victim’s machine.

T1140
Deobfuscate/Decode Files or Information
GroupAPT38

APT38 has used the RC4 algorithm to decrypt configuration data.

T1204.001
Malicious Link
GroupAPT38

APT38 has used links to execute a malicious Visual Basic script.

T1204.002
Malicious File
GroupAPT38

APT38 has attempted to lure victims into enabling malicious macros within email attachments. Additionally, APT38 has used malicious Word documents and shortcut files.

T1218.005
Mshta
GroupAPT38

APT38 has used a renamed version of `mshta.exe` to execute malicious HTML files.

T1218.007
Msiexec
GroupAPT38

APT38 has used `msiexec.exe` to execute malicious files.

T1218.011
Rundll32
GroupAPT38

APT38 has used rundll32.exe to execute binaries, scripts, and Control Panel Item files and to execute code via proxy to avoid triggering security tools.

T1480.002
Mutual Exclusion
GroupAPT38

APT38 has created a mutex to avoid duplicate execution.

T1518.001
Security Software Discovery
GroupAPT38

APT38 has identified security software, configurations, defensive tools, and sensors installed on a compromised system.

T1548.002
Bypass User Account Control
GroupAPT38

APT38 has used the legitimate application `ieinstal.exe` to bypass UAC.

T1553.005
Mark-of-the-Web Bypass
GroupAPT38

APT38 has used ISO and VHD files to deploy malware and to bypass Mark-of-the-Web (MOTW) security measures.

T1583.001
Domains
GroupAPT38

APT38 has created fake domains to imitate legitimate venture capital or bank domains.

T1685
Disable or Modify Tools
GroupAPT38

APT38 has unhooked DLLs to disable endpoint detection and response (EDR) or anti-virus (AV) tools.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.