ATT&CKReferencesCISA AA24-038A PRC Critical Infrastructure February 2024

CISA AA24-038A PRC Critical Infrastructure February 2024

CISA et al.. (2024, February 7). PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure. Retrieved May 15, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples64

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupVolt Typhoon

Volt Typhoon has attempted to access hashed credentials from the LSASS process memory space.

T1003.003
NTDS
GroupVolt Typhoon

Volt Typhoon has used ntds.util to create domain controller installation media containing usernames and password hashes.

T1005
Data from Local System
GroupVolt Typhoon

Volt Typhoon has stolen files from a sensitive file server and the Active Directory database from targeted environments, and used Wevtutil to extract event log information.

T1006
Direct Volume Access
GroupVolt Typhoon

Volt Typhoon has executed the Windows-native `vssadmin` command to create volume shadow copies.

T1007
System Service Discovery
GroupVolt Typhoon

Volt Typhoon has used `net start` to list running services.

T1010
Application Window Discovery
GroupVolt Typhoon

Volt Typhoon has collected window title information from compromised systems.

T1012
Query Registry
GroupVolt Typhoon

Volt Typhoon has queried the Registry on compromised systems, `reg query hklm\software\`, for information on installed software including PuTTY.

T1016.001
Internet Connection Discovery
GroupVolt Typhoon

Volt Typhoon has employed Ping to check network connectivity.

T1021.001
Remote Desktop Protocol
GroupVolt Typhoon

Volt Typhoon has moved laterally to the Domain Controller via RDP using a compromised account with domain administrator privileges.

T1027.002
Software Packing
GroupVolt Typhoon

Volt Typhoon has used the Ultimate Packer for Executables (UPX) to obfuscate the FRP client files BrightmetricAgent.exe and SMSvcService.ex) and the port scanning utility ScanLine.

T1033
System Owner/User Discovery
GroupVolt Typhoon

Volt Typhoon has used public tools and executed the PowerShell command `Get-EventLog security -instanceid 4624` to identify associated user and computer account names.

T1036.005
Match Legitimate Resource Name or Location
GroupVolt Typhoon

Volt Typhoon has used legitimate looking filenames for compressed copies of the ntds.dit database and used names including cisco_up.exe, cl64.exe, vm3dservice.exe, watchdogd.exe, Win.exe, WmiPreSV.exe, and WmiPrvSE.exe for the Earthworm and Fast Reverse Proxy tools.

T1046
Network Service Discovery
GroupVolt Typhoon

Volt Typhoon has used commercial tools, LOTL utilities, and appliances already present on the system for network service discovery.

T1047
Windows Management Instrumentation
GroupVolt Typhoon

Volt Typhoon has leveraged WMIC for execution, remote system discovery, and to create and use temporary directories.

T1056.001
Keylogging
GroupVolt Typhoon

Volt Typhoon has created and accessed a file named rult3uil.log on compromised domain controllers to capture keypresses and command execution.

T1057
Process Discovery
GroupVolt Typhoon

Volt Typhoon has enumerated running processes on targeted systems including through the use of Tasklist.

T1059.001
PowerShell
GroupVolt Typhoon

Volt Typhoon has used PowerShell including for remote system discovery.

T1059.003
Windows Command Shell
GroupVolt Typhoon

Volt Typhoon has used the Windows command line to perform hands-on-keyboard activities in targeted environments including for discovery.

T1059.004
Unix Shell
GroupVolt Typhoon

Volt Typhoon has used Brightmetricagent.exe which contains a command- line interface (CLI) library that can leverage command shells including Z Shell (zsh).

T1068
Exploitation for Privilege Escalation
GroupVolt Typhoon

Volt Typhoon has gained initial access by exploiting privilege escalation vulnerabilities in the operating system or network services.

T1069
Permission Groups Discovery
GroupVolt Typhoon

Volt Typhoon has used commercial tools, LOTL utilities, and appliances already present on the system for group and user discovery.

T1070.004
File Deletion
GroupVolt Typhoon

Volt Typhoon has run `rd /S` to delete their working directories and deleted systeminfo.dat from `C:\Users\Public\Documentsfiles`.

T1078
Valid Accounts
GroupVolt Typhoon

Volt Typhoon relies primarily on valid credentials for persistence.

T1078.002
Domain Accounts
GroupVolt Typhoon

Volt Typhoon has used compromised domain accounts to authenticate to devices on compromised networks.

T1083
File and Directory Discovery
GroupVolt Typhoon

Volt Typhoon has enumerated directories containing vulnerability testing and cyber related content and facilities data such as construction drawings.

T1087.001
Local Account
GroupVolt Typhoon

Volt Typhoon has executed `net user` and `quser` to enumerate local account information.

T1090
Proxy
GroupVolt Typhoon

Volt Typhoon has used compromised devices and customized versions of open source tools such as FRP (Fast Reverse Proxy), Earthworm, and Impacket to proxy network traffic.

T1090.001
Internal Proxy
GroupVolt Typhoon

Volt Typhoon has used the built-in netsh `port proxy` command to create proxies on compromised systems to facilitate access.

T1090.003
Multi-hop Proxy
GroupVolt Typhoon

Volt Typhoon has used multi-hop proxies for command-and-control infrastructure.

T1105
Ingress Tool Transfer
GroupVolt Typhoon

Volt Typhoon has downloaded an outdated version of comsvcs.dll to a compromised domain controller in a non-standard folder.

T1112
Modify Registry
GroupVolt Typhoon

Volt Typhoon has used `netsh` to create a PortProxy Registry modification on a compromised server running the Paessler Router Traffic Grapher (PRTG).

T1113
Screen Capture
GroupVolt Typhoon

Volt Typhoon has obtained a screenshot of the victim's system using the gdi32.dll and gdiplus.dll libraries.

T1120
Peripheral Device Discovery
GroupVolt Typhoon

Volt Typhoon has obtained victim's screen dimension and display device information.

T1124
System Time Discovery
GroupVolt Typhoon

Volt Typhoon has obtained the victim's system timezone.

T1133
External Remote Services
GroupVolt Typhoon

Volt Typhoon has used VPNs to connect to victim environments and enable post-exploitation actions.

T1190
Exploit Public-Facing Application
GroupVolt Typhoon

Volt Typhoon has gained initial access through exploitation of multiple vulnerabilities in internet-facing software and appliances such as Fortinet, Ivanti (formerly Pulse Secure), NETGEAR, Citrix, and Cisco.

T1217
Browser Information Discovery
GroupVolt Typhoon

Volt Typhoon has targeted the browsing history of network administrators.

T1218
System Binary Proxy Execution
GroupVolt Typhoon

Volt Typhoon has used native tools and processes including living off the land binaries or “LOLBins" to maintain and expand access to the victim networks.

T1518
Software Discovery
GroupVolt Typhoon

Volt Typhoon has queried the Registry on compromised systems for information on installed software.

T1552
Unsecured Credentials
GroupVolt Typhoon

Volt Typhoon has obtained credentials insecurely stored on targeted network appliances.

T1552.004
Private Keys
GroupVolt Typhoon

Volt Typhoon has accessed a Local State file that contains the AES key used to encrypt passwords stored in the Chrome browser.

T1555.003
Credentials from Web Browsers
GroupVolt Typhoon

Volt Typhoon has targeted network administrator browser data including browsing history and stored credentials.

T1560.001
Archive via Utility
GroupVolt Typhoon

Volt Typhoon has archived the ntds.dit database as a multi-volume password-protected archive with 7-Zip.

T1584.003
Virtual Private Server
GroupVolt Typhoon

Volt Typhoon has compromised Virtual Private Servers (VPS) to proxy C2 traffic.

T1584.004
Server
GroupVolt Typhoon

Volt Typhoon has used compromised Paessler Router Traffic Grapher (PRTG) servers from other organizations for C2.

T1584.005
Botnet
GroupVolt Typhoon

Volt Typhoon has used compromised Cisco and NETGEAR end-of-life SOHO routers implanted with KV Botnet malware to support operations.

T1587.004
Exploits
GroupVolt Typhoon

Volt Typhoon has exploited zero-day vulnerabilities for initial access.

T1588.002
Tool
GroupVolt Typhoon

Volt Typhoon has used legitimate network and forensic tools and customized versions of open-source tools for C2.

T1588.006
Vulnerabilities
GroupVolt Typhoon

Volt Typhoon has used publicly available exploit code for initial access.

T1589
Gather Victim Identity Information
GroupVolt Typhoon

Volt Typhoon has gathered victim identify information during pre-compromise reconnaissance.

Showing the first 50.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.