ATT&CKReferencesSymantec Buckeye

Symantec Buckeye

Symantec Security Response. (2016, September 6). Buckeye cyberespionage group shifts gaze from US to Hong Kong. Retrieved September 26, 2016.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software2

Campaigns0

None recorded.

Procedure examples27

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupAPT3

APT3 has used a tool to dump credentials by injecting itself into lsass.exe and triggering with the argument "dig."

T1012
Query Registry
MalwareOSInfo

OSInfo queries the registry to look for information about Terminal Services.

T1016
System Network Configuration Discovery
GroupAPT3

A keylogging tool used by APT3 gathers network information from the victim, including the MAC address, IP address, WINS, DHCP server, and gateway.

T1016
System Network Configuration Discovery
MalwareOSInfo

OSInfo discovers the current domain information.

T1018
Remote System Discovery
MalwareOSInfo

OSInfo performs a connection test to discover remote systems in the network

T1018
Remote System Discovery
GroupAPT3

APT3 has a tool that can detect the existence of remote systems.

T1021.002
SMB/Windows Admin Shares
GroupAPT3

APT3 will copy files over to Windows Admin Shares (like ADMIN$) as part of lateral movement.

T1027
Obfuscated Files or Information
GroupAPT3

APT3 obfuscates files or information to help evade defensive measures.

T1049
System Network Connections Discovery
GroupAPT3

APT3 has a tool that can enumerate current network connections.

T1049
System Network Connections Discovery
MalwareOSInfo

OSInfo enumerates the current network connections similar to net use .

T1053.005
Scheduled Task
MalwareRemoteCMD

RemoteCMD can execute commands remotely by creating a new schedule task on the remote system

T1056.001
Keylogging
GroupAPT3

APT3 has used a keylogging tool that records keystrokes in encrypted files.

T1059.003
Windows Command Shell
GroupAPT3

An APT3 downloader uses the Windows command "cmd.exe" /C whoami. The group also uses a tool to execute commands on remote computers.

T1069
Permission Groups Discovery
GroupAPT3

APT3 has a tool that can enumerate the permissions associated with Windows groups.

T1069.001
Local Groups
MalwareOSInfo

OSInfo has enumerated the local administrators group.

T1069.002
Domain Groups
MalwareOSInfo

OSInfo specifically looks for Domain Admins and power users within the domain.

T1078.002
Domain Accounts
GroupAPT3

APT3 leverages valid accounts after gaining credentials for use within the victim domain.

T1082
System Information Discovery
MalwareOSInfo

OSInfo discovers information about the infected machine.

T1082
System Information Discovery
GroupAPT3

APT3 has a tool that can obtain information about the local system.

T1087.001
Local Account
GroupAPT3

APT3 has used a tool that can obtain info about local and global group users, power users, and administrators.

T1087.001
Local Account
MalwareOSInfo

OSInfo enumerates local and domain users

T1087.002
Domain Account
MalwareOSInfo

OSInfo enumerates local and domain users

T1105
Ingress Tool Transfer
MalwareRemoteCMD

RemoteCMD copies a file over to the remote system before execution.

T1135
Network Share Discovery
MalwareOSInfo

OSInfo discovers shares on the network

T1552.001
Credentials In Files
GroupAPT3

APT3 has a tool that can locate credentials in files on the file system such as those from Firefox or Chrome.

T1555.003
Credentials from Web Browsers
GroupAPT3

APT3 has used tools to dump passwords from browsers.

T1569.002
Service Execution
MalwareRemoteCMD

RemoteCMD can execute commands remotely by creating a new service on the remote system.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.