ATT&CKReferencesFireEye SUNBURST Backdoor December 2020

FireEye SUNBURST Backdoor December 2020

FireEye. (2020, December 13). Highly Evasive Attacker Leverages SolarWinds Supply Chain to Compromise Multiple Global Victims With SUNBURST Backdoor. Retrieved January 4, 2021.

Open the source

Techniques1

Groups1

Software1

Campaigns1

Procedure examples38

TechniqueUsed byProcedure example
T1001.001
Junk Data
MalwareSUNBURST

SUNBURST added junk bytes to its C2 over HTTP.

T1001.002
Steganography
MalwareSUNBURST

SUNBURST C2 data attempted to appear as benign XML related to .NET assemblies or as a faux JSON blob.

T1001.003
Protocol or Service Impersonation
MalwareSUNBURST

SUNBURST masqueraded its network traffic as the Orion Improvement Program (OIP) protocol.

T1005
Data from Local System
MalwareSUNBURST

SUNBURST collected information from a compromised host.

T1007
System Service Discovery
MalwareSUNBURST

SUNBURST collected a list of service names that were hashed using a FNV-1a + XOR algorithm to check against similarly-hashed hardcoded blocklists.

T1012
Query Registry
MalwareSUNBURST

SUNBURST collected the registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid from compromised hosts.

T1012
Query Registry
MalwareTEARDROP

TEARDROP checked that HKU\SOFTWARE\Microsoft\CTF existed before decoding its embedded payload.

T1016
System Network Configuration Discovery
MalwareSUNBURST

SUNBURST collected all network interface MAC addresses that are up and not loopback devices, as well as IP address, DHCP configuration, and domain information.

T1027
Obfuscated Files or Information
MalwareTEARDROP

TEARDROP created and read from a file with a fake JPG header, and its payload was encrypted with a simple rotating XOR cipher.

T1027
Obfuscated Files or Information
MalwareSUNBURST

SUNBURST obfuscated collected system information using a FNV-1a + XOR algorithm.

T1033
System Owner/User Discovery
MalwareSUNBURST

SUNBURST collected the username from a compromised host.

T1036.005
Match Legitimate Resource Name or Location
MalwareTEARDROP

TEARDROP files had names that resembled legitimate Window file and directory names.

T1047
Windows Management Instrumentation
MalwareSUNBURST

SUNBURST used the WMI query Select * From Win32_SystemDriver to retrieve a driver listing.

T1053.005
Scheduled Task
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used `scheduler` and `schtasks` to create new tasks on remote host as part of their lateral movement. They manipulated scheduled tasks by updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration. APT29 also created a scheduled task to maintain SUNSPOT persistence when the host booted.

T1057
Process Discovery
MalwareSUNBURST

SUNBURST collected a list of process names that were hashed using a FNV-1a + XOR algorithm to check against similarly-hashed hardcoded blocklists.

T1070
Indicator Removal
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 temporarily replaced legitimate utilities with their own, executed their payload, and then restored the original file.

T1070.004
File Deletion
MalwareSUNBURST

SUNBURST had a command to delete files.

T1070.004
File Deletion
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 routinely removed their tools, including custom backdoors, once remote access was achieved.

T1071.001
Web Protocols
MalwareSUNBURST

SUNBURST communicated via HTTP GET or HTTP POST requests to third party servers for C2.

T1071.004
DNS
MalwareSUNBURST

SUNBURST used DNS for C2 traffic designed to mimic normal SolarWinds API communications.

T1078
Valid Accounts
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used different compromised credentials for remote access and to move laterally.

T1082
System Information Discovery
MalwareSUNBURST

SUNBURST collected hostname and OS version.

T1083
File and Directory Discovery
MalwareSUNBURST

SUNBURST had commands to enumerate files and directories.

T1105
Ingress Tool Transfer
MalwareSUNBURST

SUNBURST delivered different payloads, including TEARDROP in at least one instance.

T1105
Ingress Tool Transfer
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 downloaded additional malware, such as TEARDROP and Cobalt Strike, onto a compromised host following initial access.

T1112
Modify Registry
MalwareSUNBURST

SUNBURST had commands that allow an attacker to write or delete registry keys, and was observed stopping services by setting their HKLM\SYSTEM\CurrentControlSet\services\\[service_name]\\Start registry entries to value 4. It also deleted previously-created Image File Execution Options (IFEO) Debugger registry values and registry keys related to HTTP proxy to clean up traces of its activity.

T1124
System Time Discovery
MalwareSUNBURST

SUNBURST collected device `UPTIME`.

T1132.001
Standard Encoding
MalwareSUNBURST

SUNBURST used Base64 encoding in its C2 traffic.

T1140
Deobfuscate/Decode Files or Information
MalwareTEARDROP

TEARDROP was decoded using a custom rolling XOR algorithm to execute a customized Cobalt Strike payload.

T1195.002
Compromise Software Supply Chain
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 gained initial network access to some victims via a trojanized update of SolarWinds Orion software.

T1497.003
Time Based Checks
MalwareSUNBURST

SUNBURST remained dormant after initial access for a period of up to two weeks.

T1543.003
Windows Service
MalwareTEARDROP

TEARDROP ran as a Windows service from the c:\windows\syswow64 folder.

T1553.002
Code Signing
MalwareSUNBURST

SUNBURST was digitally signed by SolarWinds from March - May 2020.

T1553.002
Code Signing
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 was able to get SUNBURST signed by SolarWinds code signing certificates by injecting the malware into the SolarWinds Orion software lifecycle.

T1568
Dynamic Resolution
MalwareSUNBURST

SUNBURST dynamically resolved C2 infrastructure for randomly-generated subdomains within a parent domain.

T1573.001
Symmetric Cryptography
MalwareSUNBURST

SUNBURST encrypted C2 traffic using a single-byte-XOR cipher.

T1587.001
Malware
CampaignSolarWinds Compromise

For the SolarWinds Compromise, APT29 used numerous pieces of malware that were likely developed for or by the group, including SUNBURST, SUNSPOT, Raindrop, and TEARDROP.

T1665
Hide Infrastructure
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 set the hostnames of their C2 infrastructure to match legitimate hostnames in the victim environment. They also used IP addresses originating from the same country as the victim for their VPN infrastructure.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.