Mercer, W. et al. (2020, June 29). PROMETHIUM extends global reach with StrongPity3 APT. Retrieved July 20, 2020.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareStrongPity | StrongPity can identify the IP address of a compromised host. |
| T1020 Automated Exfiltration |
MalwareStrongPity | StrongPity can automatically exfiltrate collected documents to the C2 server. |
| T1027.013 Encrypted/Encoded File |
MalwareStrongPity | StrongPity has used encrypted strings in its dropper component. |
| T1036.004 Masquerade Task or Service |
MalwareStrongPity | StrongPity has named services to appear legitimate. |
| T1036.004 Masquerade Task or Service |
GroupPROMETHIUM | PROMETHIUM has named services to appear legitimate. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupPROMETHIUM | PROMETHIUM has disguised malicious installer files by bundling them with legitimate software installers. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareStrongPity | StrongPity has been bundled with legitimate software installation files for disguise. |
| T1041 Exfiltration Over C2 Channel |
MalwareStrongPity | StrongPity can exfiltrate collected documents through C2 channels. |
| T1057 Process Discovery |
MalwareStrongPity | StrongPity can determine if a user is logged in by checking to see if explorer.exe is running. |
| T1059.001 PowerShell |
MalwareStrongPity | StrongPity can use PowerShell to add files to the Windows Defender exclusions list. |
| T1070.004 File Deletion |
MalwareStrongPity | StrongPity can delete previously exfiltrated files from the compromised host. |
| T1071.001 Web Protocols |
MalwareStrongPity | StrongPity can use HTTP and HTTPS in C2 communications. |
| T1083 File and Directory Discovery |
MalwareStrongPity | StrongPity can parse the hard drive on a compromised host to identify specific file extensions. |
| T1204.002 Malicious File |
GroupPROMETHIUM | PROMETHIUM has attempted to get users to execute compromised installation files for legitimate software including compression applications, security software, browsers, file recovery applications, and other tools and utilities. |
| T1204.002 Malicious File |
MalwareStrongPity | StrongPity has been executed via compromised installation files for legitimate software including compression applications, security software, browsers, file recovery applications, and other tools and utilities. |
| T1518.001 Security Software Discovery |
MalwareStrongPity | StrongPity can identify if ESET or BitDefender antivirus are installed before dropping its payload. |
| T1543.003 Windows Service |
MalwareStrongPity | StrongPity has created new services and modified existing services for persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareStrongPity | StrongPity can use the |
| T1547.001 Registry Run Keys / Startup Folder |
GroupPROMETHIUM | PROMETHIUM has used Registry run keys to establish persistence. |
| T1560.003 Archive via Custom Method |
MalwareStrongPity | StrongPity can compress and encrypt archived files into multiple .sft files with a repeated xor encryption scheme. |
| T1564.003 Hidden Window |
MalwareStrongPity | StrongPity has the ability to hide the console window for its document search module from the user. |
| T1569.002 Service Execution |
MalwareStrongPity | StrongPity can install a service to execute itself as a service. |
| T1573.002 Asymmetric Cryptography |
MalwareStrongPity | StrongPity has encrypted C2 traffic using SSL/TLS. |
| T1587.003 Digital Certificates |
GroupPROMETHIUM | PROMETHIUM has created self-signed digital certificates for use in HTTPS C2 traffic. |
| T1680 Local Storage Discovery |
MalwareStrongPity | StrongPity can identify the hard disk volume serial number on a compromised host. |
| T1685 Disable or Modify Tools |
MalwareStrongPity | StrongPity can add directories used by the malware to the Windows Defender exclusions list to prevent detection. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.