ATT&CKReferencesTrendMicro Tropic Trooper May 2020

TrendMicro Tropic Trooper May 2020

Chen, J.. (2020, May 12). Tropic Trooper’s Back: USBferry Attack Targets Air gapped Environments. Retrieved May 20, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples43

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareUSBferry

USBferry can collect information from an air-gapped host machine.

T1016
System Network Configuration Discovery
MalwareUSBferry

USBferry can detect the infected machine's network topology using ipconfig and arp.

T1016
System Network Configuration Discovery
GroupTropic Trooper

Tropic Trooper has used scripts to collect the host's network topology.

T1018
Remote System Discovery
MalwareUSBferry

USBferry can use net view to gather information about remote systems.

T1020
Automated Exfiltration
GroupTropic Trooper

Tropic Trooper has used a copy function to automatically exfiltrate sensitive data from air-gapped systems using USB storage.

T1027.003
Steganography
GroupTropic Trooper

Tropic Trooper has used JPG files with encrypted payloads to mask their backdoor routines and evade detection.

T1027.013
Encrypted/Encoded File
GroupTropic Trooper

Tropic Trooper has encrypted configuration files.

T1036.005
Match Legitimate Resource Name or Location
GroupTropic Trooper

Tropic Trooper has hidden payloads in Flash directories and fake installer files.

T1046
Network Service Discovery
GroupTropic Trooper

Tropic Trooper used pr and an openly available tool to scan for open ports on target systems.

T1049
System Network Connections Discovery
GroupTropic Trooper

Tropic Trooper has tested if the localhost network is available and other connection capability on an infected system using command scripts.

T1049
System Network Connections Discovery
MalwareUSBferry

USBferry can use netstat and nbtstat to detect active network connections.

T1052.001
Exfiltration over USB
GroupTropic Trooper

Tropic Trooper has exfiltrated data using USB storage devices.

T1055.001
Dynamic-link Library Injection
GroupTropic Trooper

Tropic Trooper has injected a DLL backdoor into dllhost.exe and svchost.exe.

T1057
Process Discovery
MalwareUSBferry

USBferry can use tasklist to gather information about the process running on the infected system.

T1057
Process Discovery
GroupTropic Trooper

Tropic Trooper is capable of enumerating the running processes on the system using pslist.

T1059.003
Windows Command Shell
GroupTropic Trooper

Tropic Trooper has used Windows command scripts.

T1059.003
Windows Command Shell
MalwareUSBferry

USBferry can execute various Windows commands.

T1070.004
File Deletion
GroupTropic Trooper

Tropic Trooper has deleted dropper files on an infected system using command scripts.

T1071.001
Web Protocols
GroupTropic Trooper

Tropic Trooper has used HTTP in communication with the C2.

T1071.004
DNS
GroupTropic Trooper

Tropic Trooper's backdoor has communicated to the C2 over the DNS protocol.

T1078.003
Local Accounts
GroupTropic Trooper

Tropic Trooper has used known administrator account credentials to execute the backdoor directly.

T1082
System Information Discovery
GroupTropic Trooper

Tropic Trooper has detected a target system’s OS version.

T1083
File and Directory Discovery
MalwareUSBferry

USBferry can detect the victim's file or folder list.

T1083
File and Directory Discovery
GroupTropic Trooper

Tropic Trooper has monitored files' modified time.

T1087.001
Local Account
MalwareUSBferry

USBferry can use net user to gather information about local accounts.

T1091
Replication Through Removable Media
GroupTropic Trooper

Tropic Trooper has attempted to transfer USBferry from an infected USB device by copying an Autorun function to the target machine.

T1091
Replication Through Removable Media
MalwareUSBferry

USBferry can copy its installer to attached USB storage devices.

T1105
Ingress Tool Transfer
GroupTropic Trooper

Tropic Trooper has used a delivered trojan to download additional files.

T1106
Native API
GroupTropic Trooper

Tropic Trooper has used multiple Windows APIs including HttpInitialize, HttpCreateHttpHandle, and HttpAddUrl.

T1119
Automated Collection
GroupTropic Trooper

Tropic Trooper has collected information automatically using the adversary's USBferry attack.

T1120
Peripheral Device Discovery
MalwareUSBferry

USBferry can check for connected USB devices.

T1132.001
Standard Encoding
GroupTropic Trooper

Tropic Trooper has used base64 encoding to hide command strings delivered from the C2.

T1140
Deobfuscate/Decode Files or Information
GroupTropic Trooper

Tropic Trooper used shellcode with an XOR algorithm to decrypt a payload. Tropic Trooper also decrypted image files which contained a payload.

T1218.011
Rundll32
MalwareUSBferry

USBferry can execute rundll32.exe in memory to avoid detection.

T1505.003
Web Shell
GroupTropic Trooper

Tropic Trooper has started a web service in the target host and wait for the adversary to connect, acting as a web shell.

T1518
Software Discovery
GroupTropic Trooper

Tropic Trooper's backdoor could list the infected system's installed software.

T1547.001
Registry Run Keys / Startup Folder
GroupTropic Trooper

Tropic Trooper has created shortcuts in the Startup folder to establish persistence.

T1547.004
Winlogon Helper DLL
GroupTropic Trooper

Tropic Trooper has created the Registry key HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell and sets the value to establish persistence.

T1564.001
Hidden Files and Directories
GroupTropic Trooper

Tropic Trooper has created a hidden directory under C:\ProgramData\Apple\Updates\ and C:\Users\Public\Documents\Flash\.

T1566.001
Spearphishing Attachment
GroupTropic Trooper

Tropic Trooper sent spearphishing emails that contained malicious Microsoft Office and fake installer file attachments.

T1573
Encrypted Channel
GroupTropic Trooper

Tropic Trooper has encrypted traffic with the C2 to prevent network detection.

T1573.002
Asymmetric Cryptography
GroupTropic Trooper

Tropic Trooper has used SSL to connect to C2 servers.

T1680
Local Storage Discovery
GroupTropic Trooper

Tropic Trooper has detected a target system’s system volume information.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.