ATT&CKReferencesTrendMicro BlackTech June 2017

TrendMicro BlackTech June 2017

Bermejo, L., et al. (2017, June 22). Following the Trail of BlackTech’s Cyber Espionage Campaigns. Retrieved May 5, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software2

Campaigns0

None recorded.

Procedure examples24

TechniqueUsed byProcedure example
T1001.001
Junk Data
MalwarePLEAD

PLEAD samples were found to be highly obfuscated with junk code.

T1010
Application Window Discovery
MalwarePLEAD

PLEAD has the ability to list open windows on the compromised host.

T1021
Remote Services
MalwareKivars

Kivars has the ability to remotely trigger keyboard input and mouse clicks.

T1036.002
Right-to-Left Override
GroupBlackTech

BlackTech has used right-to-left-override to obfuscate the filenames of malicious e-mail attachments.

T1056.001
Keylogging
MalwareKivars

Kivars has the ability to initiate keylogging on the infected host.

T1057
Process Discovery
MalwarePLEAD

PLEAD has the ability to list processes on the compromised host.

T1070.004
File Deletion
MalwarePLEAD

PLEAD has the ability to delete files on the compromised host.

T1070.004
File Deletion
MalwareKivars

Kivars has the ability to uninstall malware from the infected host.

T1071.001
Web Protocols
MalwarePLEAD

PLEAD has used HTTP for communications with command and control (C2) servers.

T1083
File and Directory Discovery
MalwarePLEAD

PLEAD has the ability to list drives and files on the compromised host.

T1083
File and Directory Discovery
MalwareKivars

Kivars has the ability to list drives on the infected host.

T1105
Ingress Tool Transfer
MalwareKivars

Kivars has the ability to download and execute files.

T1106
Native API
MalwarePLEAD

PLEAD can use `ShellExecute` to execute applications.

T1113
Screen Capture
MalwareKivars

Kivars has the ability to capture screenshots on the infected host.

T1190
Exploit Public-Facing Application
GroupBlackTech

BlackTech has exploited a buffer overflow vulnerability in Microsoft Internet Information Services (IIS) 6.0, CVE-2017-7269, in order to establish a new HTTP or command and control (C2) server.

T1203
Exploitation for Client Execution
GroupBlackTech

BlackTech has exploited multiple vulnerabilities for execution, including Microsoft Office vulnerabilities CVE-2012-0158, CVE-2014-6352, CVE-2017-0199, and Adobe Flash CVE-2015-5119.

T1204.001
Malicious Link
MalwarePLEAD

PLEAD has been executed via malicious links in e-mails.

T1204.001
Malicious Link
GroupBlackTech

BlackTech has used e-mails with malicious links to lure victims into installing malware.

T1204.002
Malicious File
GroupBlackTech

BlackTech has used e-mails with malicious documents to lure victims into installing malware.

T1204.002
Malicious File
MalwarePLEAD

PLEAD has been executed via malicious e-mail attachments.

T1555.003
Credentials from Web Browsers
MalwarePLEAD

PLEAD can harvest saved credentials from browsers such as Google Chrome, Microsoft Internet Explorer, and Mozilla Firefox.

T1564.003
Hidden Window
MalwareKivars

Kivars has the ability to conceal its activity through hiding active windows.

T1566.001
Spearphishing Attachment
GroupBlackTech

BlackTech has used spearphishing e-mails with malicious password-protected archived files (ZIP or RAR) to deliver malware.

T1566.002
Spearphishing Link
GroupBlackTech

BlackTech has used spearphishing e-mails with links to cloud services to deliver malware.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.