ATT&CKReferencesMicrosoft NICKEL December 2021

Microsoft NICKEL December 2021

MSTIC. (2021, December 6). NICKEL targeting government organizations across Latin America and Europe. Retrieved March 18, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples34

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupKe3chang

Ke3chang has dumped credentials, including by using Mimikatz.

T1003.003
NTDS
GroupKe3chang

Ke3chang has used NTDSDump and other password dumping tools to gather credentials.

T1005
Data from Local System
MalwareNeoichor

Neoichor can upload files from a victim's machine.

T1005
Data from Local System
GroupKe3chang

Ke3chang gathered information and files from local directories for exfiltration.

T1016
System Network Configuration Discovery
MalwareNeoichor

Neoichor can gather the IP address from an infected host.

T1016
System Network Configuration Discovery
GroupKe3chang

Ke3chang has performed local network configuration discovery using ipconfig.

T1016.001
Internet Connection Discovery
MalwareNeoichor

Neoichor can check for Internet connectivity by contacting bing[.]com with the request format `bing[.]com?id=<GetTickCount>`.

T1020
Automated Exfiltration
GroupKe3chang

Ke3chang has performed frequent and scheduled data exfiltration from compromised networks.

T1027
Obfuscated Files or Information
GroupKe3chang

Ke3chang has used Base64-encoded shellcode strings.

T1033
System Owner/User Discovery
MalwareNeoichor

Neoichor can collect the user name from a victim's machine.

T1033
System Owner/User Discovery
GroupKe3chang

Ke3chang has used implants capable of collecting the signed-in username.

T1036.005
Match Legitimate Resource Name or Location
GroupKe3chang

Ke3chang has dropped their malware into legitimate installed software paths including: `C:\ProgramFiles\Realtek\Audio\HDA\AERTSr.exe`, `C:\Program Files (x86)\Foxit Software\Foxit Reader\FoxitRdr64.exe`, `C:\Program Files (x86)\Adobe\Flash Player\AddIns\airappinstaller\airappinstall.exe`, and `C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd64.exe`.

T1056.001
Keylogging
GroupKe3chang

Ke3chang has used keyloggers.

T1070
Indicator Removal
MalwareNeoichor

Neoichor can clear the browser history on a compromised host by changing the `ClearBrowsingHistoryOnExit` value to 1 in the `HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Privacy` Registry key.

T1071.001
Web Protocols
GroupKe3chang

Ke3chang malware including RoyalCli and BS2005 have communicated over HTTP with the C2 server through Internet Explorer (IE) by using the COM interface IWebBrowser2.

T1071.001
Web Protocols
MalwareNeoichor

Neoichor can use HTTP for C2 communications.

T1078
Valid Accounts
GroupKe3chang

Ke3chang has used credential dumpers or stealers to obtain legitimate credentials, which they used to gain access to victim accounts.

T1078.004
Cloud Accounts
GroupKe3chang

Ke3chang has used compromised credentials to sign into victims’ Microsoft 365 accounts.

T1082
System Information Discovery
MalwareNeoichor

Neoichor can collect the OS version and computer name from a compromised host.

T1082
System Information Discovery
GroupKe3chang

Ke3chang performs operating system information discovery using systeminfo and has used implants to identify the system language and computer name.

T1083
File and Directory Discovery
GroupKe3chang

Ke3chang uses command-line interaction to search files and directories.

T1105
Ingress Tool Transfer
GroupKe3chang

Ke3chang has used tools to download files to compromised machines.

T1105
Ingress Tool Transfer
MalwareNeoichor

Neoichor can download additional files onto a compromised host.

T1112
Modify Registry
MalwareNeoichor

Neoichor has the ability to configure browser settings by modifying Registry entries under `HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer`.

T1114.002
Remote Email Collection
GroupKe3chang

Ke3chang has used compromised credentials and a .NET tool to dump data from Microsoft Exchange mailboxes.

T1119
Automated Collection
GroupKe3chang

Ke3chang has performed frequent and scheduled data collection from victim networks.

T1133
External Remote Services
GroupKe3chang

Ke3chang has gained access through VPNs including with compromised accounts and stolen VPN certificates.

T1140
Deobfuscate/Decode Files or Information
GroupKe3chang

Ke3chang has deobfuscated Base64-encoded shellcode strings prior to loading them.

T1190
Exploit Public-Facing Application
GroupKe3chang

Ke3chang has compromised networks by exploiting Internet-facing applications, including vulnerable Microsoft Exchange and SharePoint servers.

T1559.001
Component Object Model
MalwareNeoichor

Neoichor can use the Internet Explorer (IE) COM interface to connect and receive commands from C2.

T1560.001
Archive via Utility
GroupKe3chang

Ke3chang is known to use 7Zip and RAR with passwords to encrypt data prior to exfiltration.

T1587.001
Malware
GroupKe3chang

Ke3chang has developed custom malware that allowed them to maintain persistence on victim networks.

T1614.001
System Language Discovery
GroupKe3chang

Ke3chang has used implants to collect the system language ID of a compromised machine.

T1614.001
System Language Discovery
MalwareNeoichor

Neoichor can identify the system language on a compromised host.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.