ATT&CKReferencesCybereason Kimsuky November 2020

Cybereason Kimsuky November 2020

Dahan, A. et al. (2020, November 2). Back to the Future: Inside the Kimsuky KGH Spyware Suite. Retrieved November 6, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software2

Campaigns0

None recorded.

Procedure examples36

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareKGH_SPY

KGH_SPY can send a file containing victim system information to C2.

T1027.002
Software Packing
ToolCSPY Downloader

CSPY Downloader has been packed with UPX.

T1027.013
Encrypted/Encoded File
MalwareKGH_SPY

KGH_SPY has used encrypted strings in its installer.

T1036.004
Masquerade Task or Service
ToolCSPY Downloader

CSPY Downloader has attempted to appear as a legitimate Windows service with a fake description claiming it is used to support packed applications.

T1036.005
Match Legitimate Resource Name or Location
MalwareKGH_SPY

KGH_SPY has masqueraded as a legitimate Windows tool.

T1037.001
Logon Script (Windows)
MalwareKGH_SPY

KGH_SPY has the ability to set the HKCU\Environment\UserInitMprLogonScript Registry key to execute logon scripts.

T1041
Exfiltration Over C2 Channel
MalwareKGH_SPY

KGH_SPY can exfiltrate collected information from the host to the C2 server.

T1053.005
Scheduled Task
ToolCSPY Downloader

CSPY Downloader can use the schtasks utility to bypass UAC.

T1056.001
Keylogging
MalwareKGH_SPY

KGH_SPY can perform keylogging by polling the GetAsyncKeyState() function.

T1059.001
PowerShell
MalwareKGH_SPY

KGH_SPY can execute PowerShell commands on the victim's machine.

T1059.003
Windows Command Shell
MalwareKGH_SPY

KGH_SPY has the ability to set a Registry key to run a cmd.exe command.

T1070
Indicator Removal
ToolCSPY Downloader

CSPY Downloader has the ability to remove values it writes to the Registry.

T1070.004
File Deletion
ToolCSPY Downloader

CSPY Downloader has the ability to self delete.

T1070.006
Timestomp
GroupKimsuky

Kimsuky has manipulated timestamps for creation or compilation dates to defeat anti-forensics.

T1071.001
Web Protocols
MalwareKGH_SPY

KGH_SPY can send data to C2 with HTTP POST requests.

T1071.001
Web Protocols
ToolCSPY Downloader

CSPY Downloader can use GET requests to download additional payloads from C2.

T1074.001
Local Data Staging
MalwareKGH_SPY

KGH_SPY can save collected system information to a file named "info" before exfiltration.

T1083
File and Directory Discovery
MalwareKGH_SPY

KGH_SPY can enumerate files and directories on a compromised host.

T1105
Ingress Tool Transfer
MalwareKGH_SPY

KGH_SPY has the ability to download and execute code from remote servers.

T1105
Ingress Tool Transfer
ToolCSPY Downloader

CSPY Downloader can download additional tools to a compromised host.

T1112
Modify Registry
ToolCSPY Downloader

CSPY Downloader can write to the Registry under the %windir% variable to execute tasks.

T1114.001
Local Email Collection
MalwareKGH_SPY

KGH_SPY can harvest data from mail clients.

T1140
Deobfuscate/Decode Files or Information
MalwareKGH_SPY

KGH_SPY can decrypt encrypted strings and write them to a newly created folder.

T1204.002
Malicious File
MalwareKGH_SPY

KGH_SPY has been spread through Word documents containing malicious macros.

T1204.002
Malicious File
ToolCSPY Downloader

CSPY Downloader has been delivered via malicious documents with embedded macros.

T1204.002
Malicious File
GroupKimsuky

Kimsuky has used spearphishing attachments to entice victims into opening malicious files, including LNK files disguised with tailored filenames and fake extensions. Kimsuky has also delivered malicious payloads within archive files (e.g., ZIP), which display decoy documents upon execution while running malicious code in the background.

T1497.001
System Checks
ToolCSPY Downloader

CSPY Downloader can search loaded modules, PEB structure, file paths, Registry keys, and memory to determine if it is being debugged or running in a virtual environment.

T1518
Software Discovery
MalwareKGH_SPY

KGH_SPY can collect information on installed applications.

T1548.002
Bypass User Account Control
ToolCSPY Downloader

CSPY Downloader can bypass UAC using the SilentCleanup task to execute the binary with elevated privileges.

T1553.002
Code Signing
ToolCSPY Downloader

CSPY Downloader has come signed with revoked certificates.

T1555
Credentials from Password Stores
MalwareKGH_SPY

KGH_SPY can collect credentials from WINSCP.

T1555.003
Credentials from Web Browsers
MalwareKGH_SPY

KGH_SPY has the ability to steal data from the Chrome, Edge, Firefox, Thunderbird, and Opera browsers.

T1555.004
Windows Credential Manager
MalwareKGH_SPY

KGH_SPY can collect credentials from the Windows Credential Manager.

T1566.001
Spearphishing Attachment
GroupKimsuky

Kimsuky has used emails containing Word, Excel and/or HWP (Hangul Word Processor) documents in their spearphishing campaigns. Kimsuky has also distributed emails with attached compressed zip files that contained malicious .LNK files masquerading as legitimate files. Kimsuky has delivered tailored PDF documents that contain malicious links.

T1583.001
Domains
GroupKimsuky

Kimsuky has registered domains to spoof targeted organizations and trusted third parties including search engines, web platforms, and cryptocurrency exchanges.

T1680
Local Storage Discovery
MalwareKGH_SPY

KGH_SPY can collect drive information from a compromised host.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.