Counter Threat Unit Research Team. (2023, May 24). Chinese Cyberespionage Group BRONZE SILHOUETTE Targets U.S. Government and Defense Organizations. Retrieved July 27, 2023.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.003 NTDS |
GroupVolt Typhoon | Volt Typhoon has used ntds.util to create domain controller installation media containing usernames and password hashes. |
| T1005 Data from Local System |
GroupVolt Typhoon | Volt Typhoon has stolen files from a sensitive file server and the Active Directory database from targeted environments, and used Wevtutil to extract event log information. |
| T1018 Remote System Discovery |
GroupVolt Typhoon | Volt Typhoon has used multiple methods, including Ping, to enumerate systems on compromised networks. |
| T1033 System Owner/User Discovery |
GroupVolt Typhoon | Volt Typhoon has used public tools and executed the PowerShell command `Get-EventLog security -instanceid 4624` to identify associated user and computer account names. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupVolt Typhoon | Volt Typhoon has used legitimate looking filenames for compressed copies of the ntds.dit database and used names including cisco_up.exe, cl64.exe, vm3dservice.exe, watchdogd.exe, Win.exe, WmiPreSV.exe, and WmiPrvSE.exe for the Earthworm and Fast Reverse Proxy tools. |
| T1036.008 Masquerade File Type |
GroupVolt Typhoon | Volt Typhoon has appended copies of the ntds.dit database with a .gif file extension. |
| T1047 Windows Management Instrumentation |
GroupVolt Typhoon | Volt Typhoon has leveraged WMIC for execution, remote system discovery, and to create and use temporary directories. |
| T1049 System Network Connections Discovery |
GroupVolt Typhoon | Volt Typhoon has used `netstat -ano` on compromised hosts to enumerate network connections. |
| T1057 Process Discovery |
GroupVolt Typhoon | Volt Typhoon has enumerated running processes on targeted systems including through the use of Tasklist. |
| T1059.003 Windows Command Shell |
GroupVolt Typhoon | Volt Typhoon has used the Windows command line to perform hands-on-keyboard activities in targeted environments including for discovery. |
| T1069.002 Domain Groups |
GroupVolt Typhoon | Volt Typhoon has run `net group` in compromised environments to discover domain groups. |
| T1070.004 File Deletion |
GroupVolt Typhoon | Volt Typhoon has run `rd /S` to delete their working directories and deleted systeminfo.dat from `C:\Users\Public\Documentsfiles`. |
| T1070.007 Clear Network Connection History and Configurations |
GroupVolt Typhoon | Volt Typhoon has inspected server logs to remove their IPs. |
| T1074.001 Local Data Staging |
GroupVolt Typhoon | Volt Typhoon has saved stolen files including the `ntds.dit` database and the `SYSTEM` and `SECURITY` Registry hives locally to the `C:\Windows\Temp\` directory. |
| T1078.002 Domain Accounts |
GroupVolt Typhoon | Volt Typhoon has used compromised domain accounts to authenticate to devices on compromised networks. |
| T1087.002 Domain Account |
GroupVolt Typhoon | Volt Typhoon has run `net group /dom` and `net group "Domain Admins" /dom` in compromised environments for account discovery. |
| T1140 Deobfuscate/Decode Files or Information |
GroupVolt Typhoon | Volt Typhoon has used Base64-encoded data to transfer payloads and commands, including deobfuscation via certutil. |
| T1190 Exploit Public-Facing Application |
GroupVolt Typhoon | Volt Typhoon has gained initial access through exploitation of multiple vulnerabilities in internet-facing software and appliances such as Fortinet, Ivanti (formerly Pulse Secure), NETGEAR, Citrix, and Cisco. |
| T1505.003 Web Shell |
GroupVolt Typhoon | Volt Typhoon has used webshells, including ones named AuditReport.jspx and iisstart.aspx, in compromised environments. |
| T1560.001 Archive via Utility |
GroupVolt Typhoon | Volt Typhoon has archived the ntds.dit database as a multi-volume password-protected archive with 7-Zip. |
| T1570 Lateral Tool Transfer |
GroupVolt Typhoon | Volt Typhoon has copied web shells between servers in targeted environments. |
| T1573.001 Symmetric Cryptography |
GroupVolt Typhoon | Volt Typhoon has used a version of the Awen web shell that employed AES encryption and decryption for C2 communications. |
| T1584.004 Server |
GroupVolt Typhoon | Volt Typhoon has used compromised Paessler Router Traffic Grapher (PRTG) servers from other organizations for C2. |
| T1680 Local Storage Discovery |
GroupVolt Typhoon | Volt Typhoon has discovered file system types, drive names, size, and free space on compromised systems. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.