ATT&CKReferencesGroup IB APT 41 June 2021

Group IB APT 41 June 2021

Rostovcev, N. (2021, June 10). Big airline heist APT41 likely behind a third-party attack on Air India. Retrieved August 26, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples15

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupAPT41

APT41 has used hashdump, Mimikatz, Procdump, and the Windows Credential Editor to dump password hashes from memory and authenticate to other user accounts.

T1005
Data from Local System
GroupAPT41

APT41 has uploaded files and data from a compromised host.

T1016
System Network Configuration Discovery
GroupAPT41

APT41 collected MAC addresses from victim machines.

T1036.004
Masquerade Task or Service
GroupAPT41

APT41 has created services to appear as benign system tools.

T1036.005
Match Legitimate Resource Name or Location
GroupAPT41

APT41 attempted to masquerade their files as popular anti-virus software.

T1047
Windows Management Instrumentation
GroupAPT41

APT41 used WMI in several ways, including for execution of commands via WMIEXEC as well as for persistence via PowerSploit. APT41 has executed files through Windows Management Instrumentation (WMI).

T1049
System Network Connections Discovery
GroupAPT41

APT41 has enumerated IP addresses of network resources and used the netstat command as part of network reconnaissance. The group has also used a malware variant, HIGHNOON, to enumerate active RDP sessions.

T1071.004
DNS
GroupAPT41

APT41 used DNS for C2 communications.

T1105
Ingress Tool Transfer
GroupAPT41

APT41 used certutil to download additional files. APT41 downloaded post-exploitation tools such as Cobalt Strike via command shell following initial access. APT41 has uploaded Procdump and NATBypass to a staging directory and has used these tools in follow-on activities.

T1112
Modify Registry
GroupAPT41

APT41 used a malware variant called GOODLUCK to modify the registry in order to steal credentials.

T1135
Network Share Discovery
GroupAPT41

APT41 used the net share command as part of network reconnaissance.

T1543.003
Windows Service
GroupAPT41

APT41 modified legitimate Windows services to install malware backdoors. APT41 created the StorSyncSvc service to provide persistence for Cobalt Strike.

T1547.001
Registry Run Keys / Startup Folder
GroupAPT41

APT41 created and modified startup files for persistence. APT41 added a registry key in HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost to establish persistence for Cobalt Strike.

T1553.002
Code Signing
GroupAPT41

APT41 leveraged code-signing certificates to sign malware when targeting both gaming and non-gaming organizations.

T1569.002
Service Execution
GroupAPT41

APT41 used svchost.exe and Net to execute a system service installed to launch a Cobalt Strike BEACON loader.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.