Threat Intelligence Team. (2021, December 2). SideCopy APT: Connecting lures victims, payloads to infrastructure. Retrieved June 13, 2022.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareAction RAT | Action RAT can collect local data from an infected machine. |
| T1005 Data from Local System |
MalwareAuTo Stealer | AuTo Stealer can collect data such as PowerPoint files, Word documents, Excel files, PDF files, text files, database files, and image files from an infected machine. |
| T1016 System Network Configuration Discovery |
MalwareAction RAT | Action RAT has the ability to collect the MAC address of an infected host. |
| T1016 System Network Configuration Discovery |
GroupSideCopy | SideCopy has identified the IP address of a compromised host. |
| T1027 Obfuscated Files or Information |
MalwareAction RAT | Action RAT's commands, strings, and domains can be Base64 encoded within the payload. |
| T1033 System Owner/User Discovery |
MalwareAction RAT | Action RAT has the ability to collect the username from an infected host. |
| T1033 System Owner/User Discovery |
MalwareAuTo Stealer | AuTo Stealer has the ability to collect the username from an infected host. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupSideCopy | SideCopy has used a legitimate DLL file name, `Duser.dll` to disguise a malicious remote access tool. |
| T1041 Exfiltration Over C2 Channel |
MalwareAuTo Stealer | AuTo Stealer can exfiltrate data over actor-controlled C2 servers via HTTP or TCP. |
| T1047 Windows Management Instrumentation |
MalwareAction RAT | Action RAT can use WMI to gather AV products installed on an infected host. |
| T1059.003 Windows Command Shell |
MalwareAction RAT | Action RAT can use `cmd.exe` to execute commands on an infected host. |
| T1059.003 Windows Command Shell |
MalwareAuTo Stealer | AuTo Stealer can use `cmd.exe` to execute a created batch file. |
| T1059.005 Visual Basic |
GroupSideCopy | SideCopy has sent Microsoft Office Publisher documents to victims that have embedded malicious macros that execute an hta file via calling `mshta.exe`. |
| T1071.001 Web Protocols |
MalwareAuTo Stealer | AuTo Stealer can use HTTP to communicate with its C2 servers. |
| T1071.001 Web Protocols |
MalwareAction RAT | Action RAT can use HTTP to communicate with C2 servers. |
| T1074.001 Local Data Staging |
MalwareAuTo Stealer | AuTo Stealer can store collected data from an infected host to a file named `Hostname_UserName.txt` prior to exfiltration. |
| T1082 System Information Discovery |
MalwareAuTo Stealer | AuTo Stealer has the ability to collect the hostname and OS information from an infected host. |
| T1082 System Information Discovery |
GroupSideCopy | SideCopy has identified the OS version of a compromised host. |
| T1082 System Information Discovery |
MalwareAction RAT | Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host. |
| T1083 File and Directory Discovery |
MalwareAction RAT | Action RAT has the ability to collect drive and file information on an infected machine. |
| T1095 Non-Application Layer Protocol |
MalwareAuTo Stealer | AuTo Stealer can use TCP to communicate with command and control servers. |
| T1105 Ingress Tool Transfer |
GroupSideCopy | SideCopy has delivered trojanized executables via spearphishing emails that contacts actor-controlled servers to download malicious payloads. |
| T1105 Ingress Tool Transfer |
MalwareAction RAT | Action RAT has the ability to download additional payloads onto an infected machine. |
| T1106 Native API |
GroupSideCopy | SideCopy has executed malware by calling the API function `CreateProcessW`. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareAction RAT | Action RAT can use Base64 to decode actor-controlled C2 server communications. |
| T1204.002 Malicious File |
GroupSideCopy | SideCopy has attempted to lure victims into clicking on malicious embedded archive files sent via spearphishing campaigns. |
| T1218.005 Mshta |
GroupSideCopy | SideCopy has utilized `mshta.exe` to execute a malicious hta file. |
| T1518 Software Discovery |
GroupSideCopy | SideCopy has collected browser information from a compromised host. |
| T1518.001 Security Software Discovery |
MalwareAction RAT | Action RAT can identify AV products on an infected host using the following command: `cmd.exe WMIC /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get displayName /Format:List`. |
| T1518.001 Security Software Discovery |
MalwareAuTo Stealer | AuTo Stealer has the ability to collect information about installed AV products from an infected host. |
| T1518.001 Security Software Discovery |
GroupSideCopy | SideCopy uses a loader DLL file to collect AV product names from an infected host. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareAuTo Stealer | AuTo Stealer can place malicious executables in a victim's AutoRun registry key or StartUp directory, depending on the AV product installed, to maintain persistence. |
| T1566.001 Spearphishing Attachment |
GroupSideCopy | SideCopy has sent spearphishing emails with malicious hta file attachments. |
| T1574.001 DLL |
GroupSideCopy | SideCopy has used a malicious loader DLL file to execute the `credwiz.exe` process and side-load the malicious payload `Duser.dll`. |
| T1584.001 Domains |
GroupSideCopy | SideCopy has compromised domains for some of their infrastructure, including for C2 and staging malware. |
| T1598.002 Spearphishing Attachment |
GroupSideCopy | SideCopy has crafted generic lures for spam campaigns to collect emails and credentials for targeting efforts. |
| T1608.001 Upload Malware |
GroupSideCopy | SideCopy has used compromised domains to host its malicious payloads. |
| T1614 System Location Discovery |
GroupSideCopy | SideCopy has identified the country location of a compromised host. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.