BI.ZONE Cyber Threats Research Team. (2021, May 13). From pentest to APT attack: cybercriminal group FIN7 disguises its malware as an ethical hacker’s toolkit. Retrieved February 2, 2022.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
MalwareLizar | |
| T1016 System Network Configuration Discovery |
MalwareLizar | Lizar has retrieved network information from a compromised host, such as the MAC address. |
| T1033 System Owner/User Discovery |
MalwareLizar | Lizar can collect the username from the system. |
| T1049 System Network Connections Discovery |
MalwareLizar | Lizar has a plugin to retrieve information about all active network sessions on the infected server. |
| T1055 Process Injection |
MalwareLizar | Lizar can migrate the loader into another process. |
| T1055.001 Dynamic-link Library Injection |
MalwareLizar | Lizar has used the PowerKatz plugin that can be loaded into the address space of a PowerShell process through reflective DLL loading. |
| T1055.002 Portable Executable Injection |
MalwareLizar | Lizar can execute PE files in the address space of the specified process. |
| T1057 Process Discovery |
MalwareLizar | Lizar has a plugin designed to obtain a list of processes. |
| T1059.001 PowerShell |
MalwareLizar | Lizar has used PowerShell scripts. |
| T1059.003 Windows Command Shell |
MalwareLizar | Lizar has a command to open the command-line on the infected system. |
| T1059.006 Python |
MalwareLizar | Lizar has used Python scripts (ps2x.py script and ps2p.py) to execute files on remote hosts using the Impacket library. |
| T1082 System Information Discovery |
MalwareLizar | Lizar can collect the computer name from the machine. |
| T1087.003 Email Account |
MalwareLizar | Lizar can collect email accounts from Microsoft Outlook and Mozilla Thunderbird. |
| T1105 Ingress Tool Transfer |
MalwareLizar | Lizar can download additional plugins, files, and tools. |
| T1106 Native API |
MalwareLizar | Lizar has used various Windows API functions on a victim's machine. |
| T1113 Screen Capture |
MalwareLizar | Lizar can take JPEG screenshots of an infected system. Lizar has also used a plugin to take a screenshot of the infected system. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareLizar | Lizar has decrypted its configuration data, such as the C2 IP address, ports and other network communication. |
| T1217 Browser Information Discovery |
MalwareLizar | Lizar can retrieve browser history and database files. |
| T1518.001 Security Software Discovery |
MalwareLizar | Lizar can search for processes associated with an anti-virus product from list. |
| T1555.003 Credentials from Web Browsers |
MalwareLizar | Lizar has a module to collect usernames and passwords stored in browsers. |
| T1555.004 Windows Credential Manager |
MalwareLizar | Lizar has a plugin that can retrieve credentials from Internet Explorer and Microsoft Edge using `vaultcmd.exe` and another that can collect RDP access credentials using the `CredEnumerateW` function. |
| T1560 Archive Collected Data |
MalwareLizar | Lizar has encrypted data before sending it to the server. |
| T1573 Encrypted Channel |
MalwareLizar | Lizar can support encrypted communications between the client and server. |
| T1588.002 Tool |
MalwareLizar | FIN7 has obtained and used tools such as Impacket, Mimikatz, and PsExec. |
| T1591 Gather Victim Org Information |
GroupFIN7 | FIN7 has compiled a list of victims by filtering companies by revenue using Zoominfo, which is a service that provides business information. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.