ATT&CKReferencesCISA AA20-296A Berserk Bear December 2020

CISA AA20-296A Berserk Bear December 2020

CISA. (2020, December 1). Russian State-Sponsored Advanced Persistent Threat Actor Compromises U.S. Government Targets. Retrieved December 9, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples8

TechniqueUsed byProcedure example
T1078
Valid Accounts
GroupDragonfly

Dragonfly has compromised user credentials and used valid accounts for operations.

T1083
File and Directory Discovery
GroupDragonfly

Dragonfly has used a batch script to gather folder and file names from victim hosts.

T1110
Brute Force
GroupDragonfly

Dragonfly has attempted to brute force credentials to gain access.

T1133
External Remote Services
GroupDragonfly

Dragonfly has used VPNs and Outlook Web Access (OWA) to maintain access to victim networks.

T1190
Exploit Public-Facing Application
GroupDragonfly

Dragonfly has conducted SQL injection attacks, exploited vulnerabilities CVE-2019-19781 and CVE-2020-0688 for Citrix and MS Exchange, and CVE-2018-13379 for Fortinet VPNs.

T1210
Exploitation of Remote Services
GroupDragonfly

Dragonfly has exploited a Windows Netlogon vulnerability (CVE-2020-1472) to obtain access to Windows Active Directory servers.

T1583.001
Domains
GroupDragonfly

Dragonfly has registered domains for targeting intended victims.

T1595.002
Vulnerability Scanning
GroupDragonfly

Dragonfly has scanned targeted systems for vulnerable Citrix and Microsoft Exchange services.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.