Villeneuve, N., Bennett, J. T., Moran, N., Haq, T., Scott, M., & Geers, K. (2014). OPERATION “KE3CHANG”: Targeted Attacks Against Ministries of Foreign Affairs. Retrieved November 12, 2014.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupKe3chang | Ke3chang has dumped credentials, including by using Mimikatz. |
| T1003.002 Security Account Manager |
GroupKe3chang | Ke3chang has dumped credentials, including by using gsecdump. |
| T1003.004 LSA Secrets |
GroupKe3chang | Ke3chang has dumped credentials, including by using gsecdump. |
| T1005 Data from Local System |
GroupKe3chang | Ke3chang gathered information and files from local directories for exfiltration. |
| T1007 System Service Discovery |
GroupKe3chang | Ke3chang performs service discovery using |
| T1016 System Network Configuration Discovery |
GroupKe3chang | Ke3chang has performed local network configuration discovery using |
| T1021.002 SMB/Windows Admin Shares |
GroupKe3chang | Ke3chang actors have been known to copy files to the network shares of other computers to move laterally. |
| T1036.002 Right-to-Left Override |
GroupKe3chang | Ke3chang has used the right-to-left override character in spearphishing attachment names to trick targets into executing .scr and .exe files. |
| T1041 Exfiltration Over C2 Channel |
GroupKe3chang | Ke3chang transferred compressed and encrypted RAR files containing exfiltration through the established backdoor command and control channel during operations. |
| T1049 System Network Connections Discovery |
GroupKe3chang | Ke3chang performs local network connection discovery using |
| T1057 Process Discovery |
GroupKe3chang | Ke3chang performs process discovery using |
| T1059 Command and Scripting Interpreter |
GroupKe3chang | Malware used by Ke3chang can run commands on the command-line interface. |
| T1069.002 Domain Groups |
GroupKe3chang | Ke3chang performs discovery of permission groups |
| T1082 System Information Discovery |
GroupKe3chang | Ke3chang performs operating system information discovery using |
| T1083 File and Directory Discovery |
GroupKe3chang | Ke3chang uses command-line interaction to search files and directories. |
| T1087.001 Local Account |
GroupKe3chang | Ke3chang performs account discovery using commands such as |
| T1087.002 Domain Account |
GroupKe3chang | Ke3chang performs account discovery using commands such as |
| T1132.001 Standard Encoding |
MalwareBS2005 | BS2005 uses Base64 encoding for communication in the message body of an HTTP request. |
| T1560 Archive Collected Data |
GroupKe3chang | The Ke3chang group has been known to compress data before exfiltration. |
| T1560.001 Archive via Utility |
GroupKe3chang | Ke3chang is known to use 7Zip and RAR with passwords to encrypt data prior to exfiltration. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.