ATT&CKReferencesCrowdStrike Carbon Spider August 2021

CrowdStrike Carbon Spider August 2021

Loui, E. and Reynolds, J. (2021, August 30). CARBON SPIDER Embraces Big Game Hunting, Part 1. Retrieved September 20, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples21

TechniqueUsed byProcedure example
T1005
Data from Local System
GroupFIN7

FIN7 has collected files and other sensitive information from a compromised network.

T1021.001
Remote Desktop Protocol
GroupFIN7

FIN7 has used RDP to move laterally in victim environments.

T1021.004
SSH
GroupFIN7

FIN7 has used SSH to move laterally through victim environments.

T1021.005
VNC
GroupFIN7

FIN7 has used TightVNC to control compromised hosts.

T1027.010
Command Obfuscation
GroupFIN7

FIN7 has used fragmented strings, environment variables, standard input (stdin), and native character-replacement functionalities to obfuscate commands.

T1036.005
Match Legitimate Resource Name or Location
GroupFIN7

FIN7 has attempted to run Darkside ransomware with the filename sleep.exe. Additionally, FIN7 has mimicked WsTaskLoad.exe, which is associated with the Wondershare software suite, by using a malicious executable under the same name.

T1053.005
Scheduled Task
MalwareJSS Loader

JSS Loader has the ability to launch scheduled tasks to establish persistence.

T1059.001
PowerShell
MalwareJSS Loader

JSS Loader has the ability to download and execute PowerShell scripts.

T1059.005
Visual Basic
GroupFIN7

FIN7 used VBS scripts to help perform tasks on the victim's machine.

T1059.005
Visual Basic
MalwareJSS Loader

JSS Loader can download and execute VBScript files.

T1059.007
JavaScript
MalwareJSS Loader

JSS Loader can download and execute JavaScript files.

T1078
Valid Accounts
GroupFIN7

FIN7 has harvested valid administrative credentials for lateral movement.

T1105
Ingress Tool Transfer
MalwareJSS Loader

JSS Loader has the ability to download malicious executables to a compromised host.

T1204.001
Malicious Link
GroupFIN7

FIN7 has used malicious links to lure victims into downloading malware.

T1204.002
Malicious File
GroupFIN7

FIN7 lured victims to double-click on images in the attachments they sent which would then execute the hidden LNK file. Additionally, FIN7 has used malicious Microsoft Word and Excel files and Leo VBS to distribute an updated version of JSS Loader and to distribute the Harpy backdoor.

T1210
Exploitation of Remote Services
GroupFIN7

FIN7 has exploited ZeroLogon (CVE-2020-1472) against vulnerable domain controllers.

T1486
Data Encrypted for Impact
GroupFIN7

FIN7 has encrypted virtual disk volumes on ESXi servers using a version of Darkside ransomware. Additionally, FIN7 has deployed ransomware as the end payload during big game hunting.

T1558.003
Kerberoasting
GroupFIN7

FIN7 has used Kerberoasting PowerShell commands such as, `Invoke-Kerberoast` for credential access and to enable lateral movement.

T1566.001
Spearphishing Attachment
GroupFIN7

FIN7 sent spearphishing emails with either malicious Microsoft Documents or RTF files attached.

T1566.002
Spearphishing Link
GroupFIN7

FIN7 has conducted broad phishing campaigns using malicious links. Additionally, FIN7 has sent spearphishing emails containing a typosquatted link to “ip-sccanner[.]com.”

T1567.002
Exfiltration to Cloud Storage
GroupFIN7

FIN7 has exfiltrated stolen data to the MEGA file sharing site.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.