ATT&CKReferencesMalwarebytes Kimsuky June 2021

Malwarebytes Kimsuky June 2021

Jazi, H. (2021, June 1). Kimsuky APT continues to target South Korean government using AppleSeed backdoor. Retrieved June 10, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples36

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareAppleSeed

AppleSeed can collect data on a compromised host.

T1008
Fallback Channels
MalwareAppleSeed

AppleSeed can use a second channel for C2 when the primary channel is in upload mode.

T1016
System Network Configuration Discovery
MalwareAppleSeed

AppleSeed can identify the IP of a targeted system.

T1025
Data from Removable Media
MalwareAppleSeed

AppleSeed can find and collect data from removable media devices.

T1027
Obfuscated Files or Information
MalwareAppleSeed

AppleSeed has the ability to Base64 encode its payload and custom encrypt API calls.

T1027.002
Software Packing
GroupKimsuky

Kimsuky has packed malware with UPX.

T1027.002
Software Packing
MalwareAppleSeed

AppleSeed has used UPX packers for its payload DLL.

T1036
Masquerading
MalwareAppleSeed

AppleSeed can disguise JavaScript files as PDFs.

T1036.005
Match Legitimate Resource Name or Location
MalwareAppleSeed

AppleSeed has the ability to rename its payload to ESTCommon.dll to masquerade as a DLL belonging to ESTsecurity.

T1041
Exfiltration Over C2 Channel
MalwareAppleSeed

AppleSeed can exfiltrate files via the C2 channel.

T1056.001
Keylogging
MalwareAppleSeed

AppleSeed can use GetKeyState and GetKeyboardState to capture keystrokes on the victim’s machine.

T1057
Process Discovery
MalwareAppleSeed

AppleSeed can enumerate the current process on a compromised host.

T1059.001
PowerShell
MalwareAppleSeed

AppleSeed has the ability to execute its payload via PowerShell.

T1059.007
JavaScript
MalwareAppleSeed

AppleSeed has the ability to use JavaScript to execute PowerShell.

T1070.004
File Deletion
MalwareAppleSeed

AppleSeed can delete files from a compromised host after they are exfiltrated.

T1071.001
Web Protocols
MalwareAppleSeed

AppleSeed has the ability to communicate with C2 over HTTP.

T1074.001
Local Data Staging
MalwareAppleSeed

AppleSeed can stage files in a central location prior to exfiltration.

T1082
System Information Discovery
MalwareAppleSeed

AppleSeed can identify the OS version of a targeted system.

T1083
File and Directory Discovery
MalwareAppleSeed

AppleSeed has the ability to search for .txt, .ppt, .hwp, .pdf, and .doc files in specified directories.

T1106
Native API
MalwareAppleSeed

AppleSeed has the ability to use multiple dynamically resolved API calls.

T1113
Screen Capture
MalwareAppleSeed

AppleSeed can take screenshots on a compromised host by calling a series of APIs.

T1124
System Time Discovery
MalwareAppleSeed

AppleSeed can pull a timestamp from the victim's machine.

T1134
Access Token Manipulation
MalwareAppleSeed

AppleSeed can gain system level privilege by passing SeDebugPrivilege to the AdjustTokenPrivilege API.

T1140
Deobfuscate/Decode Files or Information
MalwareAppleSeed

AppleSeed can decode its payload prior to execution.

T1204.002
Malicious File
MalwareAppleSeed

AppleSeed can achieve execution through users running malicious file attachments distributed via email.

T1204.002
Malicious File
GroupKimsuky

Kimsuky has used spearphishing attachments to entice victims into opening malicious files, including LNK files disguised with tailored filenames and fake extensions. Kimsuky has also delivered malicious payloads within archive files (e.g., ZIP), which display decoy documents upon execution while running malicious code in the background.

T1218.010
Regsvr32
MalwareAppleSeed

AppleSeed can call regsvr32.exe for execution.

T1547.001
Registry Run Keys / Startup Folder
MalwareAppleSeed

AppleSeed has the ability to create the Registry key name EstsoftAutoUpdate at HKCU\Software\Microsoft/Windows\CurrentVersion\RunOnce to establish persistence.

T1560.001
Archive via Utility
MalwareAppleSeed

AppleSeed can zip and encrypt data collected on a target system.

T1566.001
Spearphishing Attachment
GroupKimsuky

Kimsuky has used emails containing Word, Excel and/or HWP (Hangul Word Processor) documents in their spearphishing campaigns. Kimsuky has also distributed emails with attached compressed zip files that contained malicious .LNK files masquerading as legitimate files. Kimsuky has delivered tailored PDF documents that contain malicious links.

T1566.001
Spearphishing Attachment
MalwareAppleSeed

AppleSeed has been distributed to victims through malicious e-mail attachments.

T1583.001
Domains
GroupKimsuky

Kimsuky has registered domains to spoof targeted organizations and trusted third parties including search engines, web platforms, and cryptocurrency exchanges.

T1586.002
Email Accounts
GroupKimsuky

Kimsuky has compromised email accounts to send spearphishing e-mails.

T1589.002
Email Addresses
GroupKimsuky

Kimsuky has collected valid email addresses including personal accounts that were subsequently used for spearphishing and other forms of social engineering.

T1593.001
Social Media
GroupKimsuky

Kimsuky has used Twitter to monitor potential victims and to prepare targeted phishing e-mails.

T1598.003
Spearphishing Link
GroupKimsuky

Kimsuky has used links in e-mail to steal account information including web beacons for target profiling. Kimsuky has also utilized QR codes (also known as Quishing) to direct victims to malicious links through the reliance of a mobile device to scan a code with an embedded malicious URL.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.