Symantec Security Response Attack Investigation Team. (2018, April 23). New Orangeworm attack group targets the healthcare sector in the U.S., Europe, and Asia. Retrieved May 8, 2018.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1007 System Service Discovery |
MalwareKwampirs | Kwampirs collects a list of running services with the command |
| T1008 Fallback Channels |
MalwareKwampirs | Kwampirs uses a large list of C2 servers that it cycles through until a successful connection is established. |
| T1016 System Network Configuration Discovery |
MalwareKwampirs | Kwampirs collects network adapter and interface information by using the commands |
| T1018 Remote System Discovery |
MalwareKwampirs | Kwampirs collects a list of available servers with the command |
| T1021.002 SMB/Windows Admin Shares |
MalwareKwampirs | Kwampirs copies itself over network shares to move laterally on a victim network. |
| T1021.002 SMB/Windows Admin Shares |
GroupOrangeworm | Orangeworm has copied its backdoor across open network shares, including ADMIN$, C$WINDOWS, D$WINDOWS, and E$WINDOWS. |
| T1027.001 Binary Padding |
MalwareKwampirs | Before writing to disk, Kwampirs inserts a randomly generated string into the middle of the decrypted payload in an attempt to evade hash-based detections. |
| T1033 System Owner/User Discovery |
MalwareKwampirs | Kwampirs collects registered owner details by using the commands |
| T1036.004 Masquerade Task or Service |
MalwareKwampirs | Kwampirs establishes persistence by adding a new service with the display name "WMI Performance Adapter Extension" in an attempt to masquerade as a legitimate WMI service. |
| T1049 System Network Connections Discovery |
MalwareKwampirs | Kwampirs collects a list of active and listening connections by using the command |
| T1057 Process Discovery |
MalwareKwampirs | Kwampirs collects a list of running services with the command |
| T1069.001 Local Groups |
MalwareKwampirs | Kwampirs collects a list of users belonging to the local users and administrators groups with the commands |
| T1069.002 Domain Groups |
MalwareKwampirs | Kwampirs collects a list of domain groups with the command |
| T1082 System Information Discovery |
MalwareKwampirs | Kwampirs collects OS version information such as registered owner details, manufacturer details, processor type, available storage, installed patches, hostname, version info, system date, and other system information by using the commands |
| T1083 File and Directory Discovery |
MalwareKwampirs | Kwampirs collects a list of files and directories in C:\ with the command |
| T1087.001 Local Account |
MalwareKwampirs | Kwampirs collects a list of accounts with the command |
| T1135 Network Share Discovery |
MalwareKwampirs | Kwampirs collects a list of network shares with the command |
| T1140 Deobfuscate/Decode Files or Information |
MalwareKwampirs | Kwampirs decrypts and extracts a copy of its main DLL payload when executing. |
| T1201 Password Policy Discovery |
MalwareKwampirs | Kwampirs collects password policy information with the command |
| T1218.011 Rundll32 |
MalwareKwampirs | Kwampirs uses rundll32.exe in a Registry value added to establish persistence. |
| T1543.003 Windows Service |
MalwareKwampirs | Kwampirs creates a new service named WmiApSrvEx to establish persistence. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.