ATT&CKReferencesGigamon Berserk Bear October 2021

Gigamon Berserk Bear October 2021

Slowik, J. (2021, October). THE BAFFLING BERSERK BEAR: A DECADE’S ACTIVITY TARGETING CRITICAL INFRASTRUCTURE. Retrieved December 6, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples21

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareBackdoor.Oldrea

Backdoor.Oldrea collects information about the Internet adapter configuration.

T1018
Remote System Discovery
MalwareBackdoor.Oldrea

Backdoor.Oldrea can enumerate and map ICS-specific systems in victim environments.

T1046
Network Service Discovery
MalwareBackdoor.Oldrea

Backdoor.Oldrea can use a network scanning module to identify ICS-related ports.

T1055
Process Injection
MalwareBackdoor.Oldrea

Backdoor.Oldrea injects itself into explorer.exe.

T1078
Valid Accounts
GroupDragonfly

Dragonfly has compromised user credentials and used valid accounts for operations.

T1082
System Information Discovery
MalwareBackdoor.Oldrea

Backdoor.Oldrea collects information about the OS and computer name.

T1083
File and Directory Discovery
GroupDragonfly

Dragonfly has used a batch script to gather folder and file names from victim hosts.

T1105
Ingress Tool Transfer
MalwareBackdoor.Oldrea

Backdoor.Oldrea can download additional modules from C2.

T1113
Screen Capture
GroupDragonfly

Dragonfly has performed screen captures of victims, including by using a tool, scr.exe (which matched the hash of ScreenUtil).

T1187
Forced Authentication
GroupDragonfly

Dragonfly has gathered hashed user credentials over SMB using spearphishing attachments with external resource links and by modifying .LNK file icon resources to collect credentials from virtualized systems.

T1189
Drive-by Compromise
GroupDragonfly

Dragonfly has compromised targets via strategic web compromise (SWC) utilizing a custom exploit kit.

T1195.002
Compromise Software Supply Chain
GroupDragonfly

Dragonfly has placed trojanized installers for control system software on legitimate vendor app stores.

T1203
Exploitation for Client Execution
GroupDragonfly

Dragonfly has exploited CVE-2011-0611 in Adobe Flash Player to gain execution on a targeted system.

T1204.002
Malicious File
GroupDragonfly

Dragonfly has used various forms of spearphishing in attempts to get users to open malicious attachments.

T1218.011
Rundll32
MalwareBackdoor.Oldrea

Backdoor.Oldrea can use rundll32 for execution on compromised hosts.

T1547.001
Registry Run Keys / Startup Folder
MalwareBackdoor.Oldrea

Backdoor.Oldrea adds Registry Run keys to achieve persistence.

T1566.001
Spearphishing Attachment
GroupDragonfly

Dragonfly has sent emails with malicious attachments to gain initial access.

T1583.003
Virtual Private Server
GroupDragonfly

Dragonfly has acquired VPS infrastructure for use in malicious campaigns.

T1584.004
Server
GroupDragonfly

Dragonfly has compromised legitimate websites to host C2 and malware modules.

T1591.002
Business Relationships
GroupDragonfly

Dragonfly has collected open source information to identify relationships between organizations for targeting purposes.

T1608.004
Drive-by Target
GroupDragonfly

Dragonfly has compromised websites to redirect traffic and to host exploit kits.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.