FBI. (2020, September 17). Indicators of Compromise Associated with Rana Intelligence Computing, also known as Advanced Persistent Threat 39, Chafer, Cadelspy, Remexi, and ITG07. Retrieved December 10, 2020.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
GroupAPT39 | APT39 has used various tools to steal files from the compromised host. |
| T1012 Query Registry |
GroupAPT39 | APT39 has used various strains of malware to query the Registry. |
| T1027.013 Encrypted/Encoded File |
GroupAPT39 | APT39 has used malware to drop encrypted CAB files. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupAPT39 | APT39 has used malware disguised as Mozilla Firefox and a tool named mfevtpse.exe to proxy C2 communications, closely mimicking a legitimate McAfee file mfevtps.exe. |
| T1041 Exfiltration Over C2 Channel |
GroupAPT39 | APT39 has exfiltrated stolen victim data through C2 communications. |
| T1053.005 Scheduled Task |
GroupAPT39 | APT39 has created scheduled tasks for persistence. |
| T1056 Input Capture |
GroupAPT39 | APT39 has utilized tools to capture mouse movements. |
| T1056.001 Keylogging |
GroupAPT39 | APT39 has used tools for capturing keystrokes. |
| T1059 Command and Scripting Interpreter |
GroupAPT39 | APT39 has utilized custom scripts to perform internal reconnaissance. |
| T1059.005 Visual Basic |
GroupAPT39 | APT39 has utilized malicious VBS scripts in malware. |
| T1059.006 Python |
GroupAPT39 | APT39 has used a command line utility and a network scanner written in python. |
| T1059.010 AutoHotKey & AutoIT |
GroupAPT39 | APT39 has utilized AutoIt malware scripts embedded in Microsoft Office documents or malicious links. |
| T1070.004 File Deletion |
GroupAPT39 | APT39 has used malware to delete files after they are deployed on a compromised host. |
| T1071.001 Web Protocols |
GroupAPT39 | APT39 has used HTTP in communications with C2. |
| T1074.001 Local Data Staging |
GroupAPT39 | APT39 has utilized tools to aggregate data prior to exfiltration. |
| T1083 File and Directory Discovery |
GroupAPT39 | APT39 has used tools with the ability to search for files on a compromised host. |
| T1105 Ingress Tool Transfer |
GroupAPT39 | APT39 has downloaded tools to compromised hosts. |
| T1113 Screen Capture |
GroupAPT39 | APT39 has used a screen capture utility to take screenshots on a compromised host. |
| T1140 Deobfuscate/Decode Files or Information |
GroupAPT39 | APT39 has used malware to decrypt encrypted CAB files. |
| T1197 BITS Jobs |
GroupAPT39 | APT39 has used the BITS protocol to exfiltrate stolen data from a compromised host. |
| T1204.001 Malicious Link |
GroupAPT39 | APT39 has sent spearphishing emails in an attempt to lure users to click on a malicious link. |
| T1204.002 Malicious File |
GroupAPT39 | APT39 has sent spearphishing emails in an attempt to lure users to click on a malicious attachment. |
| T1546.010 AppInit DLLs |
GroupAPT39 | APT39 has used malware to set |
| T1553.006 Code Signing Policy Modification |
GroupAPT39 | APT39 has used malware to turn off the |
| T1566.001 Spearphishing Attachment |
GroupAPT39 | APT39 leveraged spearphishing emails with malicious attachments to initially compromise victims. |
| T1566.002 Spearphishing Link |
GroupAPT39 | APT39 leveraged spearphishing emails with malicious links to initially compromise victims. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.