FireEye iSIGHT Intelligence. (2017, April 6). APT10 (MenuPass Group): New Tools, Global Campaign Latest Manifestation of Longstanding Threat. Retrieved June 29, 2017.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1018 Remote System Discovery |
GroupmenuPass | menuPass uses scripts to enumerate IP ranges on the victim network. menuPass has also issued the command |
| T1036.004 Masquerade Task or Service |
MalwarePlugX | In one instance, menuPass added PlugX as a service with a display name of "Corel Writing Tools Utility." |
| T1059.003 Windows Command Shell |
MalwareSNUGRIDE | SNUGRIDE is capable of executing commands and spawning a reverse shell. |
| T1059.003 Windows Command Shell |
MalwareRedLeaves | RedLeaves can receive and execute commands with cmd.exe. It can also provide a reverse shell. |
| T1071.001 Web Protocols |
MalwareRedLeaves | RedLeaves can communicate to its C2 over HTTP and HTTPS if directed. |
| T1071.001 Web Protocols |
MalwareSNUGRIDE | SNUGRIDE communicates with its C2 server over HTTP. |
| T1083 File and Directory Discovery |
MalwareRedLeaves | RedLeaves can enumerate and search for files and directories. |
| T1083 File and Directory Discovery |
MalwareChChes | ChChes collects the victim's %TEMP% directory path and version of Internet Explorer. |
| T1090.002 External Proxy |
GroupmenuPass | menuPass has used a global service provider's IP as a proxy for C2 traffic from a victim. |
| T1105 Ingress Tool Transfer |
MalwareChChes | ChChes is capable of downloading files, including additional modules. |
| T1113 Screen Capture |
MalwareRedLeaves | RedLeaves can capture screenshots. |
| T1199 Trusted Relationship |
GroupmenuPass | menuPass has used legitimate access granted to Managed Service Providers in order to access victims of interest. |
| T1204.002 Malicious File |
GroupmenuPass | menuPass has attempted to get victims to open malicious files such as Windows Shortcuts (.lnk) and/or Microsoft Office documents, sent via email as part of spearphishing campaigns. |
| T1543.003 Windows Service |
MalwarePlugX | PlugX can be added as a service to establish persistence. PlugX also has a module to change service configurations as well as start, control, and delete services. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareSNUGRIDE | SNUGRIDE establishes persistence through a Registry Run key. |
| T1566.001 Spearphishing Attachment |
GroupmenuPass | menuPass has sent malicious Office documents via email as part of spearphishing campaigns as well as executables disguised as documents. |
| T1573.001 Symmetric Cryptography |
MalwareSNUGRIDE | SNUGRIDE encrypts C2 traffic using AES with a static key. |
| T1574.001 DLL |
MalwareRedLeaves | RedLeaves is launched through use of DLL search order hijacking to load a malicious dll. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.