ATT&CKReferencesFireEye Periscope March 2018

FireEye Periscope March 2018

FireEye. (2018, March 16). Suspected Chinese Cyber Espionage Group (TEMP.Periscope) Targeting U.S. Engineering and Maritime Industries. Retrieved April 11, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software6

Campaigns0

None recorded.

Procedure examples41

TechniqueUsed byProcedure example
T1003
OS Credential Dumping
MalwareHOMEFRY

HOMEFRY can perform credential dumping.

T1005
Data from Local System
MalwareChina Chopper

China Chopper's server component can upload local files.

T1012
Query Registry
MalwareDerusbi

Derusbi is capable of enumerating Registry keys and values.

T1018
Remote System Discovery
MalwareMURKYTOP

MURKYTOP has the capability to identify remote hosts on connected networks.

T1027.013
Encrypted/Encoded File
MalwareHOMEFRY

Some strings in HOMEFRY are obfuscated with XOR x56.

T1046
Network Service Discovery
MalwareMURKYTOP

MURKYTOP has the capability to scan for open ports on hosts in a connected network.

T1046
Network Service Discovery
MalwareChina Chopper

China Chopper's server component can spider authentication portals.

T1053.002
At
MalwareMURKYTOP

MURKYTOP has the capability to schedule remote AT jobs.

T1056.001
Keylogging
MalwareDerusbi

Derusbi is capable of logging keystrokes.

T1057
Process Discovery
MalwareDerusbi

Derusbi collects current and parent process IDs.

T1059.001
PowerShell
GroupLeviathan

Leviathan has used PowerShell for execution.

T1059.003
Windows Command Shell
MalwareMURKYTOP

MURKYTOP uses the command-line interface.

T1059.003
Windows Command Shell
MalwareHOMEFRY

HOMEFRY uses a command-line interface.

T1059.004
Unix Shell
MalwareDerusbi

Derusbi is capable of creating a remote Bash shell and executing commands.

T1069
Permission Groups Discovery
MalwareMURKYTOP

MURKYTOP has the capability to retrieve information about groups.

T1070.004
File Deletion
MalwareMURKYTOP

MURKYTOP has the capability to delete local files.

T1070.004
File Deletion
MalwareDerusbi

Derusbi is capable of deleting files. It has been observed loading a Linux Kernel Module (LKM) and then deleting it from the hard disk as well as overwriting the data with null bytes.

T1070.006
Timestomp
MalwareChina Chopper

China Chopper's server component can change the timestamp of files.

T1071.001
Web Protocols
MalwareChina Chopper

China Chopper's server component executes code sent via HTTP POST commands.

T1074.001
Local Data Staging
GroupLeviathan

Leviathan has used C:\Windows\Debug and C:\Perflogs as staging directories.

T1082
System Information Discovery
MalwareMURKYTOP

MURKYTOP has the capability to retrieve information about the OS.

T1083
File and Directory Discovery
MalwareDerusbi

Derusbi is capable of obtaining directory, file, and drive listings.

T1083
File and Directory Discovery
MalwareChina Chopper

China Chopper's server component can list directory contents.

T1087.001
Local Account
MalwareMURKYTOP

MURKYTOP has the capability to retrieve information about users on remote hosts.

T1102.001
Dead Drop Resolver
MalwareBLACKCOFFEE

BLACKCOFFEE uses Microsoft’s TechNet Web portal to obtain a dead drop resolver containing an encoded tag with the IP address of a command and control server.

T1102.002
Bidirectional Communication
MalwareBLACKCOFFEE

BLACKCOFFEE has also obfuscated its C2 traffic as normal traffic to sites such as Github.

T1102.003
One-Way Communication
GroupLeviathan

Leviathan has received C2 instructions from user profiles created on legitimate websites such as Github and TechNet.

T1105
Ingress Tool Transfer
MalwareChina Chopper

China Chopper's server component can download remote files.

T1105
Ingress Tool Transfer
GroupLeviathan

Leviathan has downloaded additional scripts and files from adversary-controlled servers.

T1110.001
Password Guessing
MalwareChina Chopper

China Chopper's server component can perform brute force password guessing against authentication portals.

T1113
Screen Capture
MalwareDerusbi

Derusbi is capable of performing screen captures.

T1123
Audio Capture
MalwareDerusbi

Derusbi is capable of performing audio captures.

T1125
Video Capture
MalwareDerusbi

Derusbi is capable of capturing video.

T1135
Network Share Discovery
MalwareMURKYTOP

MURKYTOP has the capability to retrieve information about shares on remote hosts.

T1197
BITS Jobs
GroupLeviathan

Leviathan has used BITSAdmin to download additional tools.

T1203
Exploitation for Client Execution
GroupLeviathan

Leviathan has exploited multiple Microsoft Office and .NET vulnerabilities for execution, including CVE-2017-0199, CVE-2017-8759, and CVE-2017-11882.

T1546.003
Windows Management Instrumentation Event Subscription
GroupLeviathan

Leviathan has used WMI for persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupLeviathan

Leviathan has used JavaScript to create a shortcut file in the Startup folder that points to its main backdoor.

T1547.009
Shortcut Modification
GroupLeviathan

Leviathan has used JavaScript to create a shortcut file in the Startup folder that points to its main backdoor.

T1553.002
Code Signing
GroupLeviathan

Leviathan has used stolen code signing certificates to sign malware.

T1567.002
Exfiltration to Cloud Storage
GroupLeviathan

Leviathan has used an uploader known as LUNCHMONEY that can exfiltrate files to Dropbox.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.