Chen, Joey. (2022, June 9). Aoqin Dragon | Newly-Discovered Chinese-linked APT Has Been Quietly Spying On Organizations For 10 Years. Retrieved July 14, 2022.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareMongall | Mongall has the ability to upload files from victim's machines. |
| T1007 System Service Discovery |
MalwareHeyoka Backdoor | Heyoka Backdoor can check if it is running as a service on a compromised host. |
| T1027.002 Software Packing |
GroupAoqin Dragon | Aoqin Dragon has used the Themida packer to obfuscate malicious payloads. |
| T1027.002 Software Packing |
MalwareMongall | Mongall has been packed with Themida. |
| T1027.013 Encrypted/Encoded File |
MalwareHeyoka Backdoor | Heyoka Backdoor can encrypt its payload. |
| T1036 Masquerading |
GroupAoqin Dragon | Aoqin Dragon has used fake icons including antivirus and external drives to disguise malicious payloads. |
| T1036.004 Masquerade Task or Service |
MalwareHeyoka Backdoor | Heyoka Backdoor has been named `srvdll.dll` to appear as a legitimate service. |
| T1041 Exfiltration Over C2 Channel |
MalwareMongall | Mongall can upload files and information from a compromised host to its C2 server. |
| T1055.001 Dynamic-link Library Injection |
MalwareHeyoka Backdoor | Heyoka Backdoor can inject a DLL into rundll32.exe for execution. |
| T1055.001 Dynamic-link Library Injection |
MalwareMongall | Mongall can inject a DLL into `rundll32.exe` for execution. |
| T1057 Process Discovery |
MalwareHeyoka Backdoor | Heyoka Backdoor can gather process information. |
| T1070.004 File Deletion |
MalwareHeyoka Backdoor | Heyoka Backdoor has the ability to delete folders and files from a targeted system. |
| T1071.001 Web Protocols |
MalwareMongall | Mongall can use HTTP for C2 communication. |
| T1071.004 DNS |
MalwareHeyoka Backdoor | Heyoka Backdoor can use DNS tunneling for C2 communications. |
| T1082 System Information Discovery |
MalwareMongall | Mongall can retrieve the hostname via `gethostbyname`. |
| T1083 File and Directory Discovery |
MalwareHeyoka Backdoor | Heyoka Backdoor has the ability to search the compromised host for files. |
| T1083 File and Directory Discovery |
GroupAoqin Dragon | Aoqin Dragon has run scripts to identify file formats including Microsoft Word. |
| T1091 Replication Through Removable Media |
GroupAoqin Dragon | Aoqin Dragon has used a dropper that employs a worm infection strategy using a removable device to breach a secure network environment. |
| T1105 Ingress Tool Transfer |
MalwareMongall | Mongall can download files to targeted systems. |
| T1120 Peripheral Device Discovery |
MalwareMongall | Mongall can identify removable media attached to compromised hosts. |
| T1120 Peripheral Device Discovery |
MalwareHeyoka Backdoor | Heyoka Backdoor can identify removable media attached to victim's machines. |
| T1132.001 Standard Encoding |
MalwareMongall | Mongall can use Base64 to encode information sent to its C2. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareMongall | Mongall has the ability to decrypt its payload prior to execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareHeyoka Backdoor | Heyoka Backdoor can decrypt its payload prior to execution. |
| T1203 Exploitation for Client Execution |
GroupAoqin Dragon | Aoqin Dragon has exploited CVE-2012-0158 and CVE-2010-3333 for execution against targeted systems. |
| T1204.002 Malicious File |
MalwareMongall | Mongall has relied on a user opening a malicious document for execution. |
| T1204.002 Malicious File |
GroupAoqin Dragon | Aoqin Dragon has lured victims into opening weaponized documents, fake external drives, and fake antivirus to execute malicious payloads. |
| T1204.002 Malicious File |
MalwareHeyoka Backdoor | Heyoka Backdoor has been spread through malicious document lures. |
| T1218.011 Rundll32 |
MalwareMongall | Mongall can use `rundll32.exe` for execution. |
| T1218.011 Rundll32 |
MalwareHeyoka Backdoor | Heyoka Backdoor can use rundll32.exe to gain execution. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareMongall | Mongall can establish persistence with the auto start function including using the value `EverNoteTrayUService`. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareHeyoka Backdoor | Heyoka Backdoor can establish persistence with the auto start function including using the value `EverNoteTrayUService`. |
| T1570 Lateral Tool Transfer |
GroupAoqin Dragon | Aoqin Dragon has spread malware in target networks by copying modules to folders masquerading as removable devices. |
| T1572 Protocol Tunneling |
MalwareHeyoka Backdoor | Heyoka Backdoor can use spoofed DNS requests to create a bidirectional tunnel between a compromised host and its C2 servers. |
| T1573.001 Symmetric Cryptography |
MalwareMongall | Mongall has the ability to RC4 encrypt C2 communications. |
| T1587.001 Malware |
GroupAoqin Dragon | Aoqin Dragon has used custom malware, including Mongall and Heyoka Backdoor, in their operations. |
| T1588.002 Tool |
GroupAoqin Dragon | Aoqin Dragon obtained the Heyoka open source exfiltration tool and subsequently modified it for their operations. |
| T1680 Local Storage Discovery |
MalwareHeyoka Backdoor | Heyoka Backdoor can enumerate drives on a compromised host. |
| T1680 Local Storage Discovery |
MalwareMongall | Mongall can identify drives on compromised hosts. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.