ATT&CKReferencesPalo Alto Unit 42 OutSteel SaintBot February 2022

Palo Alto Unit 42 OutSteel SaintBot February 2022

Unit 42. (2022, February 25). Spear Phishing Attacks Target Organizations in Ukraine, Payloads Include the Document Stealer OutSteel and the Downloader SaintBot. Retrieved June 9, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups2

Software2

Campaigns0

None recorded.

Procedure examples56

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareOutSteel

OutSteel can collect information from a compromised host.

T1020
Automated Exfiltration
MalwareOutSteel

OutSteel can automatically upload collected files to its C2 server.

T1027
Obfuscated Files or Information
MalwareSaint Bot

Saint Bot has been obfuscated to help avoid detection.

T1027.002
Software Packing
GroupSaint Bear

Saint Bear clones .NET assemblies from other .NET binaries as well as cloning code signing certificates from other software to obfuscate the initial loader payload.

T1027.013
Encrypted/Encoded File
GroupSaint Bear

Saint Bear initial payloads included encoded follow-on payloads located in the resources file of the first-stage loader.

T1036
Masquerading
MalwareSaint Bot

Saint Bot has renamed malicious binaries as `wallpaper.mp4` and `slideshow.mp4` to avoid detection.

T1036.005
Match Legitimate Resource Name or Location
MalwareOutSteel

OutSteel attempts to download and execute Saint Bot to a statically-defined location attempting to mimic svchost: %TEMP%\\svjhost.exe.

T1041
Exfiltration Over C2 Channel
MalwareOutSteel

OutSteel can upload files from a compromised host over its C2 channel.

T1055.012
Process Hollowing
MalwareSaint Bot

The Saint Bot loader has used API calls to spawn `MSBuild.exe` in a suspended state before injecting the decrypted Saint Bot binary into it.

T1057
Process Discovery
MalwareOutSteel

OutSteel can identify running processes on a compromised host.

T1057
Process Discovery
MalwareSaint Bot

Saint Bot has enumerated running processes on a compromised host to determine if it is running under the process name `dfrgui.exe`.

T1059
Command and Scripting Interpreter
GroupSaint Bear

Saint Bear has used the Windows Script Host (wscript) to execute intermediate files written to victim machines.

T1059.001
PowerShell
GroupSaint Bear

Saint Bear relies extensively on PowerShell execution from malicious attachments and related content to retrieve and execute follow-on payloads.

T1059.001
PowerShell
MalwareSaint Bot

Saint Bot has used PowerShell for execution.

T1059.003
Windows Command Shell
MalwareSaint Bot

Saint Bot has used `cmd.exe` and `.bat` scripts for execution.

T1059.003
Windows Command Shell
MalwareOutSteel

OutSteel has used `cmd.exe` to scan a compromised host for specific file extensions.

T1059.003
Windows Command Shell
GroupSaint Bear

Saint Bear initial loaders will also drop a malicious Windows batch file, available via open source GitHub repositories, that disables Microsoft Defender functionality.

T1059.005
Visual Basic
MalwareSaint Bot

Saint Bot has used `.vbs` scripts for execution.

T1059.007
JavaScript
GroupSaint Bear

Saint Bear has delivered malicious Microsoft Office files containing an embedded JavaScript object that would, on execution, download and execute OutSteel and Saint Bot.

T1059.010
AutoHotKey & AutoIT
MalwareOutSteel

OutSteel was developed using the AutoIT scripting language.

T1070.004
File Deletion
MalwareOutSteel

OutSteel can delete itself following the successful execution of a follow-on payload.

T1070.004
File Deletion
MalwareSaint Bot

Saint Bot can run a batch script named `del.bat` to remove any Saint Bot payload-linked files from a compromise system if anti-analysis or locale checks fail.

T1071.001
Web Protocols
MalwareOutSteel

OutSteel has used HTTP for C2 communications.

T1083
File and Directory Discovery
MalwareOutSteel

OutSteel can search for specific file extensions, including zipped files.

T1083
File and Directory Discovery
MalwareSaint Bot

Saint Bot can search a compromised host for specific files.

T1105
Ingress Tool Transfer
MalwareSaint Bot

Saint Bot can download additional files onto a compromised host.

T1105
Ingress Tool Transfer
MalwareOutSteel

OutSteel can download files from its C2 server.

T1106
Native API
MalwareSaint Bot

Saint Bot has used different API calls, including `GetProcAddress`, `VirtualAllocEx`, `WriteProcessMemory`, `CreateProcessA`, and `SetThreadContext`.

T1112
Modify Registry
GroupSaint Bear

Saint Bear will leverage malicious Windows batch scripts to modify registry values associated with Windows Defender functionality.

T1119
Automated Collection
MalwareOutSteel

OutSteel can automatically scan for and collect files with specific extensions.

T1203
Exploitation for Client Execution
GroupSaint Bear

Saint Bear has leveraged vulnerabilities in client applications such as CVE-2017-11882 in Microsoft Office to enable code execution in victim environments.

T1204.001
Malicious Link
GroupSaint Bear

Saint Bear has, in addition to email-based phishing attachments, used malicious websites masquerading as legitimate entities to host links to malicious files for user execution.

T1204.001
Malicious Link
MalwareSaint Bot

Saint Bot has relied on users to click on a malicious link delivered via a spearphishing.

T1204.001
Malicious Link
MalwareOutSteel

OutSteel has relied on a user to click a malicious link within a spearphishing email.

T1204.002
Malicious File
MalwareSaint Bot

Saint Bot has relied on users to execute a malicious attachment delivered via spearphishing.

T1204.002
Malicious File
MalwareOutSteel

OutSteel has relied on a user to execute a malicious attachment delivered via spearphishing.

T1204.002
Malicious File
GroupSaint Bear

Saint Bear relies on user interaction and execution of malicious attachments and similar for initial execution on victim systems.

T1218.010
Regsvr32
MalwareSaint Bot

Saint Bot has used `regsvr32` to execute scripts.

T1497
Virtualization/Sandbox Evasion
GroupSaint Bear

Saint Bear contains several anti-analysis and anti-virtualization checks.

T1497.001
System Checks
MalwareSaint Bot

Saint Bot has run several virtual machine and sandbox checks, including checking if `Sbiedll.dll` is present in a list of loaded modules, comparing the machine name to `HAL9TH` and the user name to `JohnDoe`, and checking the BIOS version for known virtual machine identifiers.

T1497.003
Time Based Checks
MalwareSaint Bot

Saint Bot has used the command `timeout 20` to pause the execution of its initial loader.

T1547.001
Registry Run Keys / Startup Folder
MalwareSaint Bot

Saint Bot has established persistence by being copied to the Startup directory or through the `\Software\Microsoft\Windows\CurrentVersion\Run` registry key.

T1548.002
Bypass User Account Control
MalwareSaint Bot

Saint Bot has attempted to bypass UAC using `fodhelper.exe` to escalate privileges.

T1553.002
Code Signing
GroupSaint Bear

Saint Bear has used an initial loader malware featuring a legitimate code signing certificate associated with "Electrum Technologies GmbH."

T1566.001
Spearphishing Attachment
GroupSaint Bear

Saint Bear uses a variety of file formats, such as Microsoft Office documents, ZIP archives, PDF documents, and other items as phishing attachments for initial access.

T1566.001
Spearphishing Attachment
MalwareOutSteel

OutSteel has been distributed as a malicious attachment within a spearphishing email.

T1566.001
Spearphishing Attachment
MalwareSaint Bot

Saint Bot has been distributed as malicious attachments within spearphishing emails.

T1566.002
Spearphishing Link
MalwareOutSteel

OutSteel has been distributed through malicious links contained within spearphishing emails.

T1566.002
Spearphishing Link
MalwareSaint Bot

Saint Bot has been distributed through malicious links contained within spearphishing emails.

T1570
Lateral Tool Transfer
MalwareOutSteel

OutSteel can download the Saint Bot malware for follow-on execution.

Showing the first 50.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.