ATT&CKReferencesCISA AA20-301A Kimsuky

CISA AA20-301A Kimsuky

CISA, FBI, CNMF. (2020, October 27). https://us-cert.cisa.gov/ncas/alerts/aa20-301a. Retrieved November 4, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples25

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupKimsuky

Kimsuky has gathered credentials using Mimikatz and ProcDump.

T1036.004
Masquerade Task or Service
GroupKimsuky

Kimsuky has disguised services to appear as benign software or related to operating system functions.

T1040
Network Sniffing
GroupKimsuky

Kimsuky has used the Nirsoft SniffPass network sniffer to obtain passwords sent over non-secure protocols.

T1056.001
Keylogging
GroupKimsuky

Kimsuky has used a PowerShell-based keylogger as well as a tool called MECHANICAL to log keystrokes. Kimsuky has also leveraged Native Windows API functions such as `GetAsyncKeyState()` along with others to capture keystrokes every 50 milliseconds and stores data in a file stored in the temp directory.

T1059.001
PowerShell
GroupKimsuky

Kimsuky has executed a variety of PowerShell scripts including Invoke-Mimikatz. Kimsuky has also utilized PowerShell scripts for execution, persistence, and defense evasion. Kimsuky has leveraged PowerShell’s cmdlet `Expand-Archive` to extract contents of zip files into the same directory. Kimsuky has employed ClickFix type tactics enticing victims to copy and paste malicious PowerShell commands and scripts, where the scripts ultimately led to QuasarRAT.

T1059.006
Python
GroupKimsuky

Kimsuky has used a macOS Python implant to gather data as well as MailFetcher.py code to automatically collect email data.

T1059.007
JavaScript
GroupKimsuky

Kimsuky has used JScript for logging and downloading additional tools. Kimsuky has used TRANSLATEXT, which contained four Javascript files for bypassing defenses, collecting sensitive information and screenshots, and exfiltrating data.

T1071.003
Mail Protocols
GroupKimsuky

Kimsuky has used e-mail to send exfiltrated data to C2 servers.

T1074.001
Local Data Staging
GroupKimsuky

Kimsuky has staged collected data files under C:\Program Files\Common Files\System\Ole DB\. Kimsuky has also gathered data in structured directories prior to exfiltration under the %TEMP% environment variable.

T1105
Ingress Tool Transfer
MalwareBabyShark

BabyShark has downloaded additional files from the C2.

T1112
Modify Registry
GroupKimsuky

Kimsuky has modified Registry settings for default file associations to enable all macros and for persistence. Kimsuky has also modified the registry entry for `HKCU:\Software\Microsoft\Windows\CurrentVersion\Run` registry key for persistence with the name WindowsSecurityCheck.

T1114.003
Email Forwarding Rule
GroupKimsuky

Kimsuky has set auto-forward rules on victim's e-mail accounts.

T1133
External Remote Services
GroupKimsuky

Kimsuky has used RDP to establish persistence.

T1140
Deobfuscate/Decode Files or Information
MalwareBabyShark

BabyShark has the ability to decode downloaded files prior to execution.

T1204.002
Malicious File
GroupKimsuky

Kimsuky has used spearphishing attachments to entice victims into opening malicious files, including LNK files disguised with tailored filenames and fake extensions. Kimsuky has also delivered malicious payloads within archive files (e.g., ZIP), which display decoy documents upon execution while running malicious code in the background.

T1218.005
Mshta
MalwareBabyShark

BabyShark has used mshta.exe to download and execute applications from a remote server.

T1218.005
Mshta
GroupKimsuky

Kimsuky has used mshta.exe to run malicious scripts on the system.

T1505.003
Web Shell
GroupKimsuky

Kimsuky has used modified versions of open source PHP web shells to maintain access, often adding "Dinosaur" references within the code.

T1543.003
Windows Service
GroupKimsuky

Kimsuky has created new services for persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupKimsuky

Kimsuky has placed scripts in the startup folder for persistence and modified the `HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce` Registry key.

T1547.001
Registry Run Keys / Startup Folder
MalwareBabyShark

BabyShark has added a Registry key to ensure all future macros are enabled for Microsoft Word and Excel as well as for additional persistence.

T1550.002
Pass the Hash
GroupKimsuky

Kimsuky has used pass the hash for authentication to remote access software used in C2.

T1555.003
Credentials from Web Browsers
GroupKimsuky

Kimsuky has used browser extensions including Google Chrome to steal passwords and cookies from browsers. Kimsuky has also used Nirsoft's WebBrowserPassView tool to dump the passwords obtained from victims.

T1557
Adversary-in-the-Middle
GroupKimsuky

Kimsuky has used modified versions of PHProxy to examine web traffic between the victim and the accessed website.

T1583.001
Domains
GroupKimsuky

Kimsuky has registered domains to spoof targeted organizations and trusted third parties including search engines, web platforms, and cryptocurrency exchanges.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.