ATT&CKReferencesTalos Group123

Talos Group123

Mercer, W., Rascagneres, P. (2018, January 16). Korea In The Crosshairs. Retrieved May 21, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples21

TechniqueUsed byProcedure example
T1012
Query Registry
MalwareROKRAT

ROKRAT can access the HKLM\System\CurrentControlSet\Services\mssmbios\Data\SMBiosData Registry key to obtain the System manufacturer value to identify the machine type.

T1027
Obfuscated Files or Information
GroupAPT37

APT37 obfuscates strings and payloads.

T1027.003
Steganography
GroupAPT37

APT37 uses steganography to send images to users that are embedded with shellcode.

T1033
System Owner/User Discovery
GroupAPT37

APT37 identifies the victim username.

T1055
Process Injection
GroupAPT37

APT37 injects its malware variant, ROKRAT, into the cmd.exe process.

T1057
Process Discovery
GroupAPT37

APT37's Freenki malware lists running processes using the Microsoft Windows API.

T1059.003
Windows Command Shell
GroupAPT37

APT37 has used the command-line interface.

T1059.005
Visual Basic
GroupAPT37

APT37 executes shellcode and a VBA script to decode Base64 strings.

T1071.001
Web Protocols
GroupAPT37

APT37 uses HTTPS to conceal C2 communications.

T1082
System Information Discovery
GroupAPT37

APT37 collects the computer name, the BIOS model, and execution path.

T1102.002
Bidirectional Communication
GroupAPT37

APT37 leverages social networking sites and cloud platforms (AOL, Twitter, Yandex, Mediafire, pCloud, Dropbox, and Box) for C2.

T1106
Native API
GroupAPT37

APT37 leverages the Windows API calls: VirtualAlloc(), WriteProcessMemory(), and CreateRemoteThread() for process injection.

T1203
Exploitation for Client Execution
GroupAPT37

APT37 has used exploits for Flash Player (CVE-2016-4117, CVE-2018-4878), Word (CVE-2017-0199), Internet Explorer (CVE-2020-1380 and CVE-2020-26411), and Microsoft Edge (CVE-2021-26411) for execution.

T1497.001
System Checks
MalwareROKRAT

ROKRAT can check for VMware-related files and DLLs related to sandboxes.

T1529
System Shutdown/Reboot
GroupAPT37

APT37 has used malware that will issue the command shutdown /r /t 1 to reboot a system after wiping its MBR.

T1547.001
Registry Run Keys / Startup Folder
GroupAPT37

APT37's has added persistence via the Registry key HKCU\Software\Microsoft\CurrentVersion\Run\.

T1555.003
Credentials from Web Browsers
MalwareROKRAT

ROKRAT can steal credentials stored in Web browsers by querying the sqlite database.

T1555.004
Windows Credential Manager
MalwareROKRAT

ROKRAT can steal credentials by leveraging the Windows Vault mechanism.

T1561.002
Disk Structure Wipe
GroupAPT37

APT37 has access to destructive malware that is capable of overwriting a machine's Master Boot Record (MBR).

T1566.001
Spearphishing Attachment
GroupAPT37

APT37 delivers malware using spearphishing emails with malicious HWP attachments.

T1622
Debugger Evasion
MalwareROKRAT

ROKRAT can check for debugging tools.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.