Unit 42. (2022, February 25). Spear Phishing Attacks Target Organizations in Ukraine, Payloads Include the Document Stealer OutSteel and the Downloader SaintBot. Retrieved June 9, 2022.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareOutSteel | OutSteel can collect information from a compromised host. |
| T1020 Automated Exfiltration |
MalwareOutSteel | OutSteel can automatically upload collected files to its C2 server. |
| T1027 Obfuscated Files or Information |
MalwareSaint Bot | Saint Bot has been obfuscated to help avoid detection. |
| T1027.002 Software Packing |
GroupSaint Bear | Saint Bear clones .NET assemblies from other .NET binaries as well as cloning code signing certificates from other software to obfuscate the initial loader payload. |
| T1027.013 Encrypted/Encoded File |
GroupSaint Bear | Saint Bear initial payloads included encoded follow-on payloads located in the resources file of the first-stage loader. |
| T1036 Masquerading |
MalwareSaint Bot | Saint Bot has renamed malicious binaries as `wallpaper.mp4` and `slideshow.mp4` to avoid detection. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareOutSteel | OutSteel attempts to download and execute Saint Bot to a statically-defined location attempting to mimic svchost: |
| T1041 Exfiltration Over C2 Channel |
MalwareOutSteel | OutSteel can upload files from a compromised host over its C2 channel. |
| T1055.012 Process Hollowing |
MalwareSaint Bot | The Saint Bot loader has used API calls to spawn `MSBuild.exe` in a suspended state before injecting the decrypted Saint Bot binary into it. |
| T1057 Process Discovery |
MalwareOutSteel | OutSteel can identify running processes on a compromised host. |
| T1057 Process Discovery |
MalwareSaint Bot | Saint Bot has enumerated running processes on a compromised host to determine if it is running under the process name `dfrgui.exe`. |
| T1059 Command and Scripting Interpreter |
GroupSaint Bear | Saint Bear has used the Windows Script Host (wscript) to execute intermediate files written to victim machines. |
| T1059.001 PowerShell |
GroupSaint Bear | Saint Bear relies extensively on PowerShell execution from malicious attachments and related content to retrieve and execute follow-on payloads. |
| T1059.001 PowerShell |
MalwareSaint Bot | Saint Bot has used PowerShell for execution. |
| T1059.003 Windows Command Shell |
MalwareSaint Bot | Saint Bot has used `cmd.exe` and `.bat` scripts for execution. |
| T1059.003 Windows Command Shell |
MalwareOutSteel | OutSteel has used `cmd.exe` to scan a compromised host for specific file extensions. |
| T1059.003 Windows Command Shell |
GroupSaint Bear | Saint Bear initial loaders will also drop a malicious Windows batch file, available via open source GitHub repositories, that disables Microsoft Defender functionality. |
| T1059.005 Visual Basic |
MalwareSaint Bot | Saint Bot has used `.vbs` scripts for execution. |
| T1059.007 JavaScript |
GroupSaint Bear | Saint Bear has delivered malicious Microsoft Office files containing an embedded JavaScript object that would, on execution, download and execute OutSteel and Saint Bot. |
| T1059.010 AutoHotKey & AutoIT |
MalwareOutSteel | OutSteel was developed using the AutoIT scripting language. |
| T1070.004 File Deletion |
MalwareOutSteel | OutSteel can delete itself following the successful execution of a follow-on payload. |
| T1070.004 File Deletion |
MalwareSaint Bot | Saint Bot can run a batch script named `del.bat` to remove any Saint Bot payload-linked files from a compromise system if anti-analysis or locale checks fail. |
| T1071.001 Web Protocols |
MalwareOutSteel | OutSteel has used HTTP for C2 communications. |
| T1083 File and Directory Discovery |
MalwareOutSteel | OutSteel can search for specific file extensions, including zipped files. |
| T1083 File and Directory Discovery |
MalwareSaint Bot | Saint Bot can search a compromised host for specific files. |
| T1105 Ingress Tool Transfer |
MalwareSaint Bot | Saint Bot can download additional files onto a compromised host. |
| T1105 Ingress Tool Transfer |
MalwareOutSteel | OutSteel can download files from its C2 server. |
| T1106 Native API |
MalwareSaint Bot | Saint Bot has used different API calls, including `GetProcAddress`, `VirtualAllocEx`, `WriteProcessMemory`, `CreateProcessA`, and `SetThreadContext`. |
| T1112 Modify Registry |
GroupSaint Bear | Saint Bear will leverage malicious Windows batch scripts to modify registry values associated with Windows Defender functionality. |
| T1119 Automated Collection |
MalwareOutSteel | OutSteel can automatically scan for and collect files with specific extensions. |
| T1203 Exploitation for Client Execution |
GroupSaint Bear | Saint Bear has leveraged vulnerabilities in client applications such as CVE-2017-11882 in Microsoft Office to enable code execution in victim environments. |
| T1204.001 Malicious Link |
GroupSaint Bear | Saint Bear has, in addition to email-based phishing attachments, used malicious websites masquerading as legitimate entities to host links to malicious files for user execution. |
| T1204.001 Malicious Link |
MalwareSaint Bot | Saint Bot has relied on users to click on a malicious link delivered via a spearphishing. |
| T1204.001 Malicious Link |
MalwareOutSteel | OutSteel has relied on a user to click a malicious link within a spearphishing email. |
| T1204.002 Malicious File |
MalwareSaint Bot | Saint Bot has relied on users to execute a malicious attachment delivered via spearphishing. |
| T1204.002 Malicious File |
MalwareOutSteel | OutSteel has relied on a user to execute a malicious attachment delivered via spearphishing. |
| T1204.002 Malicious File |
GroupSaint Bear | Saint Bear relies on user interaction and execution of malicious attachments and similar for initial execution on victim systems. |
| T1218.010 Regsvr32 |
MalwareSaint Bot | Saint Bot has used `regsvr32` to execute scripts. |
| T1497 Virtualization/Sandbox Evasion |
GroupSaint Bear | Saint Bear contains several anti-analysis and anti-virtualization checks. |
| T1497.001 System Checks |
MalwareSaint Bot | Saint Bot has run several virtual machine and sandbox checks, including checking if `Sbiedll.dll` is present in a list of loaded modules, comparing the machine name to `HAL9TH` and the user name to `JohnDoe`, and checking the BIOS version for known virtual machine identifiers. |
| T1497.003 Time Based Checks |
MalwareSaint Bot | Saint Bot has used the command `timeout 20` to pause the execution of its initial loader. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareSaint Bot | Saint Bot has established persistence by being copied to the Startup directory or through the `\Software\Microsoft\Windows\CurrentVersion\Run` registry key. |
| T1548.002 Bypass User Account Control |
MalwareSaint Bot | Saint Bot has attempted to bypass UAC using `fodhelper.exe` to escalate privileges. |
| T1553.002 Code Signing |
GroupSaint Bear | Saint Bear has used an initial loader malware featuring a legitimate code signing certificate associated with "Electrum Technologies GmbH." |
| T1566.001 Spearphishing Attachment |
GroupSaint Bear | Saint Bear uses a variety of file formats, such as Microsoft Office documents, ZIP archives, PDF documents, and other items as phishing attachments for initial access. |
| T1566.001 Spearphishing Attachment |
MalwareOutSteel | OutSteel has been distributed as a malicious attachment within a spearphishing email. |
| T1566.001 Spearphishing Attachment |
MalwareSaint Bot | Saint Bot has been distributed as malicious attachments within spearphishing emails. |
| T1566.002 Spearphishing Link |
MalwareOutSteel | OutSteel has been distributed through malicious links contained within spearphishing emails. |
| T1566.002 Spearphishing Link |
MalwareSaint Bot | Saint Bot has been distributed through malicious links contained within spearphishing emails. |
| T1570 Lateral Tool Transfer |
MalwareOutSteel | OutSteel can download the Saint Bot malware for follow-on execution. |
Showing the first 50.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.