ATT&CKReferencesMalwareBytes SideCopy Dec 2021

MalwareBytes SideCopy Dec 2021

Threat Intelligence Team. (2021, December 2). SideCopy APT: Connecting lures victims, payloads to infrastructure. Retrieved June 13, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software2

Campaigns0

None recorded.

Procedure examples38

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareAction RAT

Action RAT can collect local data from an infected machine.

T1005
Data from Local System
MalwareAuTo Stealer

AuTo Stealer can collect data such as PowerPoint files, Word documents, Excel files, PDF files, text files, database files, and image files from an infected machine.

T1016
System Network Configuration Discovery
MalwareAction RAT

Action RAT has the ability to collect the MAC address of an infected host.

T1016
System Network Configuration Discovery
GroupSideCopy

SideCopy has identified the IP address of a compromised host.

T1027
Obfuscated Files or Information
MalwareAction RAT

Action RAT's commands, strings, and domains can be Base64 encoded within the payload.

T1033
System Owner/User Discovery
MalwareAction RAT

Action RAT has the ability to collect the username from an infected host.

T1033
System Owner/User Discovery
MalwareAuTo Stealer

AuTo Stealer has the ability to collect the username from an infected host.

T1036.005
Match Legitimate Resource Name or Location
GroupSideCopy

SideCopy has used a legitimate DLL file name, `Duser.dll` to disguise a malicious remote access tool.

T1041
Exfiltration Over C2 Channel
MalwareAuTo Stealer

AuTo Stealer can exfiltrate data over actor-controlled C2 servers via HTTP or TCP.

T1047
Windows Management Instrumentation
MalwareAction RAT

Action RAT can use WMI to gather AV products installed on an infected host.

T1059.003
Windows Command Shell
MalwareAction RAT

Action RAT can use `cmd.exe` to execute commands on an infected host.

T1059.003
Windows Command Shell
MalwareAuTo Stealer

AuTo Stealer can use `cmd.exe` to execute a created batch file.

T1059.005
Visual Basic
GroupSideCopy

SideCopy has sent Microsoft Office Publisher documents to victims that have embedded malicious macros that execute an hta file via calling `mshta.exe`.

T1071.001
Web Protocols
MalwareAuTo Stealer

AuTo Stealer can use HTTP to communicate with its C2 servers.

T1071.001
Web Protocols
MalwareAction RAT

Action RAT can use HTTP to communicate with C2 servers.

T1074.001
Local Data Staging
MalwareAuTo Stealer

AuTo Stealer can store collected data from an infected host to a file named `Hostname_UserName.txt` prior to exfiltration.

T1082
System Information Discovery
MalwareAuTo Stealer

AuTo Stealer has the ability to collect the hostname and OS information from an infected host.

T1082
System Information Discovery
GroupSideCopy

SideCopy has identified the OS version of a compromised host.

T1082
System Information Discovery
MalwareAction RAT

Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host.

T1083
File and Directory Discovery
MalwareAction RAT

Action RAT has the ability to collect drive and file information on an infected machine.

T1095
Non-Application Layer Protocol
MalwareAuTo Stealer

AuTo Stealer can use TCP to communicate with command and control servers.

T1105
Ingress Tool Transfer
GroupSideCopy

SideCopy has delivered trojanized executables via spearphishing emails that contacts actor-controlled servers to download malicious payloads.

T1105
Ingress Tool Transfer
MalwareAction RAT

Action RAT has the ability to download additional payloads onto an infected machine.

T1106
Native API
GroupSideCopy

SideCopy has executed malware by calling the API function `CreateProcessW`.

T1140
Deobfuscate/Decode Files or Information
MalwareAction RAT

Action RAT can use Base64 to decode actor-controlled C2 server communications.

T1204.002
Malicious File
GroupSideCopy

SideCopy has attempted to lure victims into clicking on malicious embedded archive files sent via spearphishing campaigns.

T1218.005
Mshta
GroupSideCopy

SideCopy has utilized `mshta.exe` to execute a malicious hta file.

T1518
Software Discovery
GroupSideCopy

SideCopy has collected browser information from a compromised host.

T1518.001
Security Software Discovery
MalwareAction RAT

Action RAT can identify AV products on an infected host using the following command: `cmd.exe WMIC /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get displayName /Format:List`.

T1518.001
Security Software Discovery
MalwareAuTo Stealer

AuTo Stealer has the ability to collect information about installed AV products from an infected host.

T1518.001
Security Software Discovery
GroupSideCopy

SideCopy uses a loader DLL file to collect AV product names from an infected host.

T1547.001
Registry Run Keys / Startup Folder
MalwareAuTo Stealer

AuTo Stealer can place malicious executables in a victim's AutoRun registry key or StartUp directory, depending on the AV product installed, to maintain persistence.

T1566.001
Spearphishing Attachment
GroupSideCopy

SideCopy has sent spearphishing emails with malicious hta file attachments.

T1574.001
DLL
GroupSideCopy

SideCopy has used a malicious loader DLL file to execute the `credwiz.exe` process and side-load the malicious payload `Duser.dll`.

T1584.001
Domains
GroupSideCopy

SideCopy has compromised domains for some of their infrastructure, including for C2 and staging malware.

T1598.002
Spearphishing Attachment
GroupSideCopy

SideCopy has crafted generic lures for spam campaigns to collect emails and credentials for targeting efforts.

T1608.001
Upload Malware
GroupSideCopy

SideCopy has used compromised domains to host its malicious payloads.

T1614
System Location Discovery
GroupSideCopy

SideCopy has identified the country location of a compromised host.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.