ATT&CKReferencesFireEye APT10 April 2017

FireEye APT10 April 2017

FireEye iSIGHT Intelligence. (2017, April 6). APT10 (MenuPass Group): New Tools, Global Campaign Latest Manifestation of Longstanding Threat. Retrieved June 29, 2017.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software2

Campaigns0

None recorded.

Procedure examples18

TechniqueUsed byProcedure example
T1018
Remote System Discovery
GroupmenuPass

menuPass uses scripts to enumerate IP ranges on the victim network. menuPass has also issued the command net view /domain to a PlugX implant to gather information about remote systems on the network.

T1036.004
Masquerade Task or Service
MalwarePlugX

In one instance, menuPass added PlugX as a service with a display name of "Corel Writing Tools Utility."

T1059.003
Windows Command Shell
MalwareSNUGRIDE

SNUGRIDE is capable of executing commands and spawning a reverse shell.

T1059.003
Windows Command Shell
MalwareRedLeaves

RedLeaves can receive and execute commands with cmd.exe. It can also provide a reverse shell.

T1071.001
Web Protocols
MalwareRedLeaves

RedLeaves can communicate to its C2 over HTTP and HTTPS if directed.

T1071.001
Web Protocols
MalwareSNUGRIDE

SNUGRIDE communicates with its C2 server over HTTP.

T1083
File and Directory Discovery
MalwareRedLeaves

RedLeaves can enumerate and search for files and directories.

T1083
File and Directory Discovery
MalwareChChes

ChChes collects the victim's %TEMP% directory path and version of Internet Explorer.

T1090.002
External Proxy
GroupmenuPass

menuPass has used a global service provider's IP as a proxy for C2 traffic from a victim.

T1105
Ingress Tool Transfer
MalwareChChes

ChChes is capable of downloading files, including additional modules.

T1113
Screen Capture
MalwareRedLeaves

RedLeaves can capture screenshots.

T1199
Trusted Relationship
GroupmenuPass

menuPass has used legitimate access granted to Managed Service Providers in order to access victims of interest.

T1204.002
Malicious File
GroupmenuPass

menuPass has attempted to get victims to open malicious files such as Windows Shortcuts (.lnk) and/or Microsoft Office documents, sent via email as part of spearphishing campaigns.

T1543.003
Windows Service
MalwarePlugX

PlugX can be added as a service to establish persistence. PlugX also has a module to change service configurations as well as start, control, and delete services.

T1547.001
Registry Run Keys / Startup Folder
MalwareSNUGRIDE

SNUGRIDE establishes persistence through a Registry Run key.

T1566.001
Spearphishing Attachment
GroupmenuPass

menuPass has sent malicious Office documents via email as part of spearphishing campaigns as well as executables disguised as documents.

T1573.001
Symmetric Cryptography
MalwareSNUGRIDE

SNUGRIDE encrypts C2 traffic using AES with a static key.

T1574.001
DLL
MalwareRedLeaves

RedLeaves is launched through use of DLL search order hijacking to load a malicious dll.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.