Mercer, W., Rascagneres, P. (2018, January 16). Korea In The Crosshairs. Retrieved May 21, 2018.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1012 Query Registry |
MalwareROKRAT | ROKRAT can access the |
| T1027 Obfuscated Files or Information |
GroupAPT37 | APT37 obfuscates strings and payloads. |
| T1027.003 Steganography |
GroupAPT37 | APT37 uses steganography to send images to users that are embedded with shellcode. |
| T1033 System Owner/User Discovery |
GroupAPT37 | APT37 identifies the victim username. |
| T1055 Process Injection |
GroupAPT37 | APT37 injects its malware variant, ROKRAT, into the cmd.exe process. |
| T1057 Process Discovery |
GroupAPT37 | APT37's Freenki malware lists running processes using the Microsoft Windows API. |
| T1059.003 Windows Command Shell |
GroupAPT37 | APT37 has used the command-line interface. |
| T1059.005 Visual Basic |
GroupAPT37 | APT37 executes shellcode and a VBA script to decode Base64 strings. |
| T1071.001 Web Protocols |
GroupAPT37 | APT37 uses HTTPS to conceal C2 communications. |
| T1082 System Information Discovery |
GroupAPT37 | APT37 collects the computer name, the BIOS model, and execution path. |
| T1102.002 Bidirectional Communication |
GroupAPT37 | APT37 leverages social networking sites and cloud platforms (AOL, Twitter, Yandex, Mediafire, pCloud, Dropbox, and Box) for C2. |
| T1106 Native API |
GroupAPT37 | APT37 leverages the Windows API calls: VirtualAlloc(), WriteProcessMemory(), and CreateRemoteThread() for process injection. |
| T1203 Exploitation for Client Execution |
GroupAPT37 | APT37 has used exploits for Flash Player (CVE-2016-4117, CVE-2018-4878), Word (CVE-2017-0199), Internet Explorer (CVE-2020-1380 and CVE-2020-26411), and Microsoft Edge (CVE-2021-26411) for execution. |
| T1497.001 System Checks |
MalwareROKRAT | ROKRAT can check for VMware-related files and DLLs related to sandboxes. |
| T1529 System Shutdown/Reboot |
GroupAPT37 | APT37 has used malware that will issue the command |
| T1547.001 Registry Run Keys / Startup Folder |
GroupAPT37 | APT37's has added persistence via the Registry key |
| T1555.003 Credentials from Web Browsers |
MalwareROKRAT | ROKRAT can steal credentials stored in Web browsers by querying the sqlite database. |
| T1555.004 Windows Credential Manager |
MalwareROKRAT | ROKRAT can steal credentials by leveraging the Windows Vault mechanism. |
| T1561.002 Disk Structure Wipe |
GroupAPT37 | APT37 has access to destructive malware that is capable of overwriting a machine's Master Boot Record (MBR). |
| T1566.001 Spearphishing Attachment |
GroupAPT37 | APT37 delivers malware using spearphishing emails with malicious HWP attachments. |
| T1622 Debugger Evasion |
MalwareROKRAT | ROKRAT can check for debugging tools. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.