ATT&CKReferencesFireEye APT32 May 2017

FireEye APT32 May 2017

Carr, N.. (2017, May 14). Cyber Espionage is Alive and Well: APT32 and the Threat to Global Corporations. Retrieved June 18, 2017.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software4

Campaigns0

None recorded.

Procedure examples29

TechniqueUsed byProcedure example
T1010
Application Window Discovery
MalwareSOUNDBITE

SOUNDBITE is capable of enumerating application windows.

T1012
Query Registry
MalwareWINDSHIELD

WINDSHIELD can gather Registry values.

T1027.010
Command Obfuscation
GroupAPT32

APT32 has used the `Invoke-Obfuscation` framework to obfuscate their PowerShell.

T1027.013
Encrypted/Encoded File
GroupAPT32

APT32 has performed code obfuscation, including encoding payloads using Base64 and using a framework called "Dont-Kill-My-Cat (DKMC). APT32 also encrypts the library used for network exfiltration with AES-256 in CBC mode in their macOS backdoor.

T1033
System Owner/User Discovery
MalwareWINDSHIELD

WINDSHIELD can gather the victim user name.

T1036.004
Masquerade Task or Service
GroupAPT32

APT32 has used hidden or non-printing characters to help masquerade service names, such as appending a Unicode no-break space character to a legitimate service name. APT32 has also impersonated the legitimate Flash installer file name "install_flashplayer.exe".

T1047
Windows Management Instrumentation
MalwareKOMPROGO

KOMPROGO is capable of running WMI queries.

T1053.005
Scheduled Task
GroupAPT32

APT32 has used scheduled tasks to persist on victim systems.

T1059.001
PowerShell
GroupAPT32

APT32 has used PowerShell-based tools, PowerShell one-liners, and shellcode loaders for execution.

T1059.003
Windows Command Shell
MalwareKOMPROGO

KOMPROGO is capable of creating a reverse shell.

T1059.003
Windows Command Shell
MalwarePHOREAL

PHOREAL is capable of creating reverse shell.

T1068
Exploitation for Privilege Escalation
GroupAPT32

APT32 has used CVE-2016-7255 to escalate privileges.

T1070.004
File Deletion
MalwareWINDSHIELD

WINDSHIELD is capable of file deletion along with other file system interaction.

T1070.006
Timestomp
GroupAPT32

APT32 has used scheduled task raw XML with a backdated timestamp of June 2, 2016. The group has also set the creation time of the files dropped by the second stage of the exploit to match the creation time of kernel32.dll. Additionally, APT32 has used a random value to modify the timestamp of the file storing the clientID.

T1071.004
DNS
MalwareSOUNDBITE

SOUNDBITE communicates via DNS for C2.

T1072
Software Deployment Tools
GroupAPT32

APT32 compromised McAfee ePO to move laterally by distributing malware as a software deployment task.

T1078.003
Local Accounts
GroupAPT32

APT32 has used legitimate local admin account credentials.

T1082
System Information Discovery
MalwareWINDSHIELD

WINDSHIELD can gather the victim computer name.

T1082
System Information Discovery
MalwareKOMPROGO

KOMPROGO is capable of retrieving information about the infected system.

T1082
System Information Discovery
MalwareSOUNDBITE

SOUNDBITE is capable of gathering system information.

T1083
File and Directory Discovery
MalwareSOUNDBITE

SOUNDBITE is capable of enumerating and manipulating files and directories.

T1095
Non-Application Layer Protocol
MalwareWINDSHIELD

WINDSHIELD C2 traffic can communicate via TCP raw sockets.

T1095
Non-Application Layer Protocol
MalwarePHOREAL

PHOREAL communicates via ICMP for C2.

T1112
Modify Registry
MalwarePHOREAL

PHOREAL is capable of manipulating the Registry.

T1112
Modify Registry
MalwareSOUNDBITE

SOUNDBITE is capable of modifying the Registry.

T1218.010
Regsvr32
GroupAPT32

APT32 created a Scheduled Task/Job that used regsvr32.exe to execute a COM scriptlet that dynamically downloaded a backdoor and injected it into memory. The group has also used regsvr32 to run their backdoor.

T1564.003
Hidden Window
GroupAPT32

APT32 has used the WindowStyle parameter to conceal PowerShell windows.

T1588.002
Tool
GroupAPT32

APT32 has obtained and used tools such as Mimikatz and Cobalt Strike, and a variety of other open-source tools from GitHub.

T1685.005
Clear Windows Event Logs
GroupAPT32

APT32 has cleared select event log entries.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.