ATT&CKReferencesSymantec Dragonfly

Symantec Dragonfly

Symantec Security Response. (2014, June 30). Dragonfly: Cyberespionage Attacks Against Energy Suppliers. Retrieved April 8, 2016.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software2

Campaigns0

None recorded.

Procedure examples19

TechniqueUsed byProcedure example
T1003
OS Credential Dumping
MalwareTrojan.Karagany

Trojan.Karagany can dump passwords and save them into \ProgramData\Mail\MailAg\pwds.txt.

T1016
System Network Configuration Discovery
MalwareBackdoor.Oldrea

Backdoor.Oldrea collects information about the Internet adapter configuration.

T1027.002
Software Packing
MalwareTrojan.Karagany

Trojan.Karagany samples sometimes use common binary packers such as UPX and Aspack on top of a custom Delphi binary packer.

T1033
System Owner/User Discovery
MalwareBackdoor.Oldrea

Backdoor.Oldrea collects the current username from the victim.

T1055
Process Injection
MalwareBackdoor.Oldrea

Backdoor.Oldrea injects itself into explorer.exe.

T1057
Process Discovery
MalwareBackdoor.Oldrea

Backdoor.Oldrea collects information about running processes.

T1057
Process Discovery
MalwareTrojan.Karagany

Trojan.Karagany can use Tasklist to collect a list of running tasks.

T1070.004
File Deletion
MalwareBackdoor.Oldrea

Backdoor.Oldrea contains a cleanup module that removes traces of itself from the victim.

T1074.001
Local Data Staging
MalwareTrojan.Karagany

Trojan.Karagany can create directories to store plugin output and stage data for exfiltration.

T1082
System Information Discovery
MalwareBackdoor.Oldrea

Backdoor.Oldrea collects information about the OS and computer name.

T1083
File and Directory Discovery
MalwareBackdoor.Oldrea

Backdoor.Oldrea collects information about available drives, default browser, desktop file list, My Documents, Internet history, program files, and root of available drives. It also searches for ICS-related software files.

T1087.003
Email Account
MalwareBackdoor.Oldrea

Backdoor.Oldrea collects address book information from Outlook.

T1105
Ingress Tool Transfer
MalwareTrojan.Karagany

Trojan.Karagany can upload, download, and execute files on the victim.

T1113
Screen Capture
MalwareTrojan.Karagany

Trojan.Karagany can take a desktop screenshot and save the file into \ProgramData\Mail\MailAg\shot.png.

T1132.001
Standard Encoding
MalwareBackdoor.Oldrea

Some Backdoor.Oldrea samples use standard Base64 + bzip2, and some use standard Base64 + reverse XOR + RSA-2048 to decrypt data received from C2 servers.

T1547.001
Registry Run Keys / Startup Folder
MalwareBackdoor.Oldrea

Backdoor.Oldrea adds Registry Run keys to achieve persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareTrojan.Karagany

Trojan.Karagany can create a link to itself in the Startup folder to automatically start itself upon system restart.

T1555.003
Credentials from Web Browsers
MalwareBackdoor.Oldrea

Some Backdoor.Oldrea samples contain a publicly available Web browser password recovery tool.

T1560
Archive Collected Data
MalwareBackdoor.Oldrea

Backdoor.Oldrea writes collected data to a temporary file in an encrypted form before exfiltration to a C2 server.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.