ATT&CKReferencesCISA AA21-200A APT40 July 2021

CISA AA21-200A APT40 July 2021

CISA. (2021, July 19). (AA21-200A) Joint Cybersecurity Advisory – Tactics, Techniques, and Procedures of Indicted APT40 Actors Associated with China’s MSS Hainan State Security Department. Retrieved August 12, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples24

TechniqueUsed byProcedure example
T1027.003
Steganography
GroupLeviathan

Leviathan has used steganography to hide stolen data inside other files stored on Github.

T1041
Exfiltration Over C2 Channel
GroupLeviathan

Leviathan has exfiltrated data over its C2 channel.

T1059.001
PowerShell
GroupLeviathan

Leviathan has used PowerShell for execution.

T1074.001
Local Data Staging
GroupLeviathan

Leviathan has used C:\Windows\Debug and C:\Perflogs as staging directories.

T1074.002
Remote Data Staging
GroupLeviathan

Leviathan has staged data remotely prior to exfiltration.

T1078
Valid Accounts
GroupLeviathan

Leviathan has obtained valid accounts to gain initial access.

T1090.003
Multi-hop Proxy
GroupLeviathan

Leviathan has used multi-hop proxies to disguise the source of their malicious traffic.

T1133
External Remote Services
GroupLeviathan

Leviathan has used external remote services such as virtual private networks (VPN) to gain initial access.

T1189
Drive-by Compromise
GroupLeviathan

Leviathan has infected victims using watering holes.

T1203
Exploitation for Client Execution
GroupLeviathan

Leviathan has exploited multiple Microsoft Office and .NET vulnerabilities for execution, including CVE-2017-0199, CVE-2017-8759, and CVE-2017-11882.

T1204.001
Malicious Link
GroupLeviathan

Leviathan has sent spearphishing email links attempting to get a user to click.

T1204.002
Malicious File
GroupLeviathan

Leviathan has sent spearphishing attachments attempting to get a user to click.

T1505.003
Web Shell
GroupLeviathan

Leviathan relies on web shells for an initial foothold as well as persistence into the victim's systems.

T1534
Internal Spearphishing
GroupLeviathan

Leviathan has conducted internal spearphishing within the victim's environment for lateral movement.

T1560
Archive Collected Data
GroupLeviathan

Leviathan has archived victim's data prior to exfiltration.

T1566.001
Spearphishing Attachment
GroupLeviathan

Leviathan has sent spearphishing emails with malicious attachments, including .rtf, .doc, and .xls files.

T1566.002
Spearphishing Link
GroupLeviathan

Leviathan has sent spearphishing emails with links, often using a fraudulent lookalike domain and stolen branding.

T1572
Protocol Tunneling
GroupLeviathan

Leviathan has used protocol tunneling to further conceal C2 communications and infrastructure.

T1583.001
Domains
GroupLeviathan

Leviathan has established domains that impersonate legitimate entities to use for targeting efforts.

T1585.001
Social Media Accounts
GroupLeviathan

Leviathan has created new social media accounts for targeting efforts.

T1585.002
Email Accounts
GroupLeviathan

Leviathan has created new email accounts for targeting efforts.

T1586.001
Social Media Accounts
GroupLeviathan

Leviathan has compromised social media accounts to conduct social engineering attacks.

T1586.002
Email Accounts
GroupLeviathan

Leviathan has compromised email accounts to conduct social engineering attacks.

T1589.001
Credentials
GroupLeviathan

Leviathan has collected compromised credentials to use for targeting efforts.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.