Carr, N.. (2017, May 14). Cyber Espionage is Alive and Well: APT32 and the Threat to Global Corporations. Retrieved June 18, 2017.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1010 Application Window Discovery |
MalwareSOUNDBITE | SOUNDBITE is capable of enumerating application windows. |
| T1012 Query Registry |
MalwareWINDSHIELD | WINDSHIELD can gather Registry values. |
| T1027.010 Command Obfuscation |
GroupAPT32 | APT32 has used the `Invoke-Obfuscation` framework to obfuscate their PowerShell. |
| T1027.013 Encrypted/Encoded File |
GroupAPT32 | APT32 has performed code obfuscation, including encoding payloads using Base64 and using a framework called "Dont-Kill-My-Cat (DKMC). APT32 also encrypts the library used for network exfiltration with AES-256 in CBC mode in their macOS backdoor. |
| T1033 System Owner/User Discovery |
MalwareWINDSHIELD | WINDSHIELD can gather the victim user name. |
| T1036.004 Masquerade Task or Service |
GroupAPT32 | APT32 has used hidden or non-printing characters to help masquerade service names, such as appending a Unicode no-break space character to a legitimate service name. APT32 has also impersonated the legitimate Flash installer file name "install_flashplayer.exe". |
| T1047 Windows Management Instrumentation |
MalwareKOMPROGO | KOMPROGO is capable of running WMI queries. |
| T1053.005 Scheduled Task |
GroupAPT32 | APT32 has used scheduled tasks to persist on victim systems. |
| T1059.001 PowerShell |
GroupAPT32 | APT32 has used PowerShell-based tools, PowerShell one-liners, and shellcode loaders for execution. |
| T1059.003 Windows Command Shell |
MalwareKOMPROGO | KOMPROGO is capable of creating a reverse shell. |
| T1059.003 Windows Command Shell |
MalwarePHOREAL | PHOREAL is capable of creating reverse shell. |
| T1068 Exploitation for Privilege Escalation |
GroupAPT32 | APT32 has used CVE-2016-7255 to escalate privileges. |
| T1070.004 File Deletion |
MalwareWINDSHIELD | WINDSHIELD is capable of file deletion along with other file system interaction. |
| T1070.006 Timestomp |
GroupAPT32 | APT32 has used scheduled task raw XML with a backdated timestamp of June 2, 2016. The group has also set the creation time of the files dropped by the second stage of the exploit to match the creation time of kernel32.dll. Additionally, APT32 has used a random value to modify the timestamp of the file storing the clientID. |
| T1071.004 DNS |
MalwareSOUNDBITE | SOUNDBITE communicates via DNS for C2. |
| T1072 Software Deployment Tools |
GroupAPT32 | APT32 compromised McAfee ePO to move laterally by distributing malware as a software deployment task. |
| T1078.003 Local Accounts |
GroupAPT32 | APT32 has used legitimate local admin account credentials. |
| T1082 System Information Discovery |
MalwareWINDSHIELD | WINDSHIELD can gather the victim computer name. |
| T1082 System Information Discovery |
MalwareKOMPROGO | KOMPROGO is capable of retrieving information about the infected system. |
| T1082 System Information Discovery |
MalwareSOUNDBITE | SOUNDBITE is capable of gathering system information. |
| T1083 File and Directory Discovery |
MalwareSOUNDBITE | SOUNDBITE is capable of enumerating and manipulating files and directories. |
| T1095 Non-Application Layer Protocol |
MalwareWINDSHIELD | WINDSHIELD C2 traffic can communicate via TCP raw sockets. |
| T1095 Non-Application Layer Protocol |
MalwarePHOREAL | PHOREAL communicates via ICMP for C2. |
| T1112 Modify Registry |
MalwarePHOREAL | PHOREAL is capable of manipulating the Registry. |
| T1112 Modify Registry |
MalwareSOUNDBITE | SOUNDBITE is capable of modifying the Registry. |
| T1218.010 Regsvr32 |
GroupAPT32 | APT32 created a Scheduled Task/Job that used regsvr32.exe to execute a COM scriptlet that dynamically downloaded a backdoor and injected it into memory. The group has also used regsvr32 to run their backdoor. |
| T1564.003 Hidden Window |
GroupAPT32 | APT32 has used the WindowStyle parameter to conceal PowerShell windows. |
| T1588.002 Tool |
GroupAPT32 | APT32 has obtained and used tools such as Mimikatz and Cobalt Strike, and a variety of other open-source tools from GitHub. |
| T1685.005 Clear Windows Event Logs |
GroupAPT32 | APT32 has cleared select event log entries. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.