FireEye. (2020, December 13). Highly Evasive Attacker Leverages SolarWinds Supply Chain to Compromise Multiple Global Victims With SUNBURST Backdoor. Retrieved January 4, 2021.
| Technique | Used by | Procedure example |
|---|---|---|
| T1001.001 Junk Data |
MalwareSUNBURST | SUNBURST added junk bytes to its C2 over HTTP. |
| T1001.002 Steganography |
MalwareSUNBURST | SUNBURST C2 data attempted to appear as benign XML related to .NET assemblies or as a faux JSON blob. |
| T1001.003 Protocol or Service Impersonation |
MalwareSUNBURST | SUNBURST masqueraded its network traffic as the Orion Improvement Program (OIP) protocol. |
| T1005 Data from Local System |
MalwareSUNBURST | SUNBURST collected information from a compromised host. |
| T1007 System Service Discovery |
MalwareSUNBURST | SUNBURST collected a list of service names that were hashed using a FNV-1a + XOR algorithm to check against similarly-hashed hardcoded blocklists. |
| T1012 Query Registry |
MalwareSUNBURST | SUNBURST collected the registry value |
| T1012 Query Registry |
MalwareTEARDROP | TEARDROP checked that |
| T1016 System Network Configuration Discovery |
MalwareSUNBURST | SUNBURST collected all network interface MAC addresses that are up and not loopback devices, as well as IP address, DHCP configuration, and domain information. |
| T1027 Obfuscated Files or Information |
MalwareTEARDROP | TEARDROP created and read from a file with a fake JPG header, and its payload was encrypted with a simple rotating XOR cipher. |
| T1027 Obfuscated Files or Information |
MalwareSUNBURST | SUNBURST obfuscated collected system information using a FNV-1a + XOR algorithm. |
| T1033 System Owner/User Discovery |
MalwareSUNBURST | SUNBURST collected the username from a compromised host. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareTEARDROP | TEARDROP files had names that resembled legitimate Window file and directory names. |
| T1047 Windows Management Instrumentation |
MalwareSUNBURST | SUNBURST used the WMI query |
| T1053.005 Scheduled Task |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used `scheduler` and `schtasks` to create new tasks on remote host as part of their lateral movement. They manipulated scheduled tasks by updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration. APT29 also created a scheduled task to maintain SUNSPOT persistence when the host booted. |
| T1057 Process Discovery |
MalwareSUNBURST | SUNBURST collected a list of process names that were hashed using a FNV-1a + XOR algorithm to check against similarly-hashed hardcoded blocklists. |
| T1070 Indicator Removal |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 temporarily replaced legitimate utilities with their own, executed their payload, and then restored the original file. |
| T1070.004 File Deletion |
MalwareSUNBURST | SUNBURST had a command to delete files. |
| T1070.004 File Deletion |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 routinely removed their tools, including custom backdoors, once remote access was achieved. |
| T1071.001 Web Protocols |
MalwareSUNBURST | SUNBURST communicated via HTTP GET or HTTP POST requests to third party servers for C2. |
| T1071.004 DNS |
MalwareSUNBURST | SUNBURST used DNS for C2 traffic designed to mimic normal SolarWinds API communications. |
| T1078 Valid Accounts |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used different compromised credentials for remote access and to move laterally. |
| T1082 System Information Discovery |
MalwareSUNBURST | SUNBURST collected hostname and OS version. |
| T1083 File and Directory Discovery |
MalwareSUNBURST | SUNBURST had commands to enumerate files and directories. |
| T1105 Ingress Tool Transfer |
MalwareSUNBURST | SUNBURST delivered different payloads, including TEARDROP in at least one instance. |
| T1105 Ingress Tool Transfer |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 downloaded additional malware, such as TEARDROP and Cobalt Strike, onto a compromised host following initial access. |
| T1112 Modify Registry |
MalwareSUNBURST | SUNBURST had commands that allow an attacker to write or delete registry keys, and was observed stopping services by setting their |
| T1124 System Time Discovery |
MalwareSUNBURST | SUNBURST collected device `UPTIME`. |
| T1132.001 Standard Encoding |
MalwareSUNBURST | SUNBURST used Base64 encoding in its C2 traffic. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareTEARDROP | TEARDROP was decoded using a custom rolling XOR algorithm to execute a customized Cobalt Strike payload. |
| T1195.002 Compromise Software Supply Chain |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 gained initial network access to some victims via a trojanized update of SolarWinds Orion software. |
| T1497.003 Time Based Checks |
MalwareSUNBURST | SUNBURST remained dormant after initial access for a period of up to two weeks. |
| T1543.003 Windows Service |
MalwareTEARDROP | TEARDROP ran as a Windows service from the |
| T1553.002 Code Signing |
MalwareSUNBURST | SUNBURST was digitally signed by SolarWinds from March - May 2020. |
| T1553.002 Code Signing |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 was able to get SUNBURST signed by SolarWinds code signing certificates by injecting the malware into the SolarWinds Orion software lifecycle. |
| T1568 Dynamic Resolution |
MalwareSUNBURST | SUNBURST dynamically resolved C2 infrastructure for randomly-generated subdomains within a parent domain. |
| T1573.001 Symmetric Cryptography |
MalwareSUNBURST | SUNBURST encrypted C2 traffic using a single-byte-XOR cipher. |
| T1587.001 Malware |
CampaignSolarWinds Compromise | For the SolarWinds Compromise, APT29 used numerous pieces of malware that were likely developed for or by the group, including SUNBURST, SUNSPOT, Raindrop, and TEARDROP. |
| T1665 Hide Infrastructure |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 set the hostnames of their C2 infrastructure to match legitimate hostnames in the victim environment. They also used IP addresses originating from the same country as the victim for their VPN infrastructure. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.