Faou, M. (2023, August 10). MoustachedBouncer: Espionage against foreign diplomats in Belarus. Retrieved September 25, 2023.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareNightClub | NightClub can use a file monitor to steal specific files from targeted systems. |
| T1005 Data from Local System |
MalwareSharpDisco | SharpDisco has dropped a recent-files stealer plugin to `C:\Users\Public\WinSrcNT\It11.exe`. |
| T1010 Application Window Discovery |
MalwareNightClub | NightClub can use `GetForegroundWindow` to enumerate the active window. |
| T1027 Obfuscated Files or Information |
MalwareNightClub | NightClub can obfuscate strings using the congruential generator `(LCG): staten+1 = (690069 × staten + 1) mod 232`. |
| T1027.002 Software Packing |
GroupMoustachedBouncer | MoustachedBouncer has used malware plugins packed with Themida. |
| T1036.004 Masquerade Task or Service |
MalwareNightClub | NightClub has created a service named `WmdmPmSp` to spoof a Windows Media service. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareNightClub | NightClub has chosen file names to appear legitimate including EsetUpdate-0117583943.exe for its dropper. |
| T1041 Exfiltration Over C2 Channel |
MalwareSharpDisco | SharpDisco can load a plugin to exfiltrate stolen files to SMB shares also used in C2. |
| T1041 Exfiltration Over C2 Channel |
MalwareNightClub | NightClub can use SMTP and DNS for file exfiltration and C2. |
| T1053.005 Scheduled Task |
MalwareDisco | Disco can create a scheduled task to run every minute for persistence. |
| T1053.005 Scheduled Task |
MalwareSharpDisco | SharpDisco can create scheduled tasks to execute reverse shells that read and write data to and from specified SMB shares. |
| T1056.001 Keylogging |
MalwareNightClub | NightClub can use a plugin for keylogging. |
| T1057 Process Discovery |
MalwareNightClub | NightClub has the ability to use `GetWindowThreadProcessId` to identify the process behind a specified window. |
| T1059.001 PowerShell |
GroupMoustachedBouncer | MoustachedBouncer has used plugins to execute PowerShell scripts. |
| T1059.003 Windows Command Shell |
MalwareSharpDisco | SharpDisco can use `cmd.exe` to execute plugins and to send command output to specified SMB shares. |
| T1059.007 JavaScript |
GroupMoustachedBouncer | MoustachedBouncer has used JavaScript to deliver malware hosted on HTML pages. |
| T1068 Exploitation for Privilege Escalation |
GroupMoustachedBouncer | MoustachedBouncer has exploited CVE-2021-1732 to execute malware components with elevated rights. |
| T1070.006 Timestomp |
MalwareNightClub | NightClub can modify the Creation, Access, and Write timestamps for malicious DLLs to match those of the genuine Windows DLL user32.dll. |
| T1071.002 File Transfer Protocols |
MalwareDisco | Disco can use SMB to transfer files. |
| T1071.002 File Transfer Protocols |
MalwareSharpDisco | SharpDisco has the ability to transfer data between SMB shares. |
| T1071.003 Mail Protocols |
MalwareNightClub | NightClub can use emails for C2 communications. |
| T1071.004 DNS |
MalwareNightClub | NightClub can use a DNS tunneling plugin to exfiltrate data by adding it to the subdomain portion of a DNS request. |
| T1074.001 Local Data Staging |
MalwareNightClub | NightClub has copied captured files and keystrokes to the `%TEMP%` directory of compromised hosts. |
| T1074.002 Remote Data Staging |
GroupMoustachedBouncer | MoustachedBouncer has used plugins to save captured screenshots to `.\AActdata\` on an SMB share. |
| T1083 File and Directory Discovery |
MalwareNightClub | NightClub can use a file monitor to identify .lnk, .doc, .docx, .xls, .xslx, and .pdf files. |
| T1083 File and Directory Discovery |
MalwareSharpDisco | SharpDisco can identify recently opened files by using an LNK format parser to extract the original file path from LNK files found in either `%USERPROFILE%\Recent` (Windows XP) or `%APPDATA%\Microsoft\Windows\Recent` (newer Windows versions) . |
| T1090 Proxy |
GroupMoustachedBouncer | MoustachedBouncer has used a reverse proxy tool similar to the GitHub repository revsocks. |
| T1105 Ingress Tool Transfer |
MalwareSharpDisco | SharpDisco has been used to download a Python interpreter to `C:\Users\Public\WinTN\WinTN.exe` as well as other plugins from external sources. |
| T1105 Ingress Tool Transfer |
MalwareDisco | Disco can download files to targeted systems via SMB. |
| T1105 Ingress Tool Transfer |
MalwareNightClub | NightClub can load multiple additional plugins on an infected host. |
| T1106 Native API |
MalwareNightClub | NightClub can use multiple native APIs including `GetKeyState`, `GetForegroundWindow`, `GetWindowThreadProcessId`, and `GetKeyboardLayout`. |
| T1106 Native API |
MalwareSharpDisco | SharpDisco can leverage Native APIs through plugins including `GetLogicalDrives`. |
| T1112 Modify Registry |
MalwareNightClub | NightClub can modify the Registry to set the ServiceDLL for a service created by the malware for persistence. |
| T1113 Screen Capture |
GroupMoustachedBouncer | MoustachedBouncer has used plugins to take screenshots on targeted systems. |
| T1113 Screen Capture |
MalwareNightClub | NightClub can load a module to call `CreateCompatibleDC` and `GdipSaveImageToStream` for screen capture. |
| T1120 Peripheral Device Discovery |
MalwareSharpDisco | SharpDisco has dropped a plugin to monitor external drives to `C:\Users\Public\It3.exe`. |
| T1120 Peripheral Device Discovery |
MalwareNightClub | NightClub has the ability to monitor removable drives. |
| T1123 Audio Capture |
MalwareNightClub | NightClub can load a module to leverage the LAME encoder and `mciSendStringW` to control and capture audio. |
| T1132.002 Non-Standard Encoding |
MalwareNightClub | NightClub has used a non-standard encoding in DNS tunneling removing any `=` from the result of base64 encoding, and replacing `/` characters with `-s` and `+` characters with `-p`. |
| T1204.002 Malicious File |
MalwareDisco | Disco has been executed through inducing user interaction with malicious .zip and .msi files. |
| T1543.003 Windows Service |
MalwareNightClub | NightClub has created a Windows service named `WmdmPmSp` to establish persistence. |
| T1564.003 Hidden Window |
MalwareSharpDisco | SharpDisco can hide windows using `ProcessWindowStyle.Hidden`. |
| T1659 Content Injection |
GroupMoustachedBouncer | MoustachedBouncer has injected content into DNS, HTTP, and SMB replies to redirect specifically-targeted victims to a fake Windows Update page to download malware. |
| T1659 Content Injection |
MalwareDisco | Disco has achieved initial access and execution through content injection into DNS, HTTP, and SMB replies to targeted hosts that redirect them to download malicious files. |
| T1680 Local Storage Discovery |
MalwareSharpDisco | SharpDisco can use a plugin to enumerate system drives. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.