ATT&CKReferencesKorean FSI TA505 2020

Korean FSI TA505 2020

Financial Security Institute. (2020, February 28). Profiling of TA505 Threat Group That Continues to Attack the Financial Sector. Retrieved July 14, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples32

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareFlawedAmmyy

FlawedAmmyy has collected information and files from a compromised machine.

T1033
System Owner/User Discovery
MalwareFlawedAmmyy

FlawedAmmyy enumerates the current user during the initial infection.

T1041
Exfiltration Over C2 Channel
MalwareSDBbot

SDBbot has sent collected data from a compromised host to its C2 servers.

T1041
Exfiltration Over C2 Channel
MalwareFlawedAmmyy

FlawedAmmyy has sent data collected from a compromised host to its C2 servers.

T1056
Input Capture
MalwareFlawedAmmyy

FlawedAmmyy can collect mouse events.

T1056.001
Keylogging
MalwareFlawedAmmyy

FlawedAmmyy can collect keyboard events.

T1057
Process Discovery
MalwareSDBbot

SDBbot can enumerate a list of running processes on a compromised machine.

T1059.001
PowerShell
MalwareFlawedAmmyy

FlawedAmmyy has used PowerShell to execute commands.

T1059.003
Windows Command Shell
MalwareFlawedAmmyy

FlawedAmmyy has used `cmd` to execute commands on a compromised host.

T1069.001
Local Groups
MalwareFlawedAmmyy

FlawedAmmyy enumerates the privilege level of the victim during the initial infection.

T1070.004
File Deletion
MalwareFlawedAmmyy

FlawedAmmyy can execute batch scripts to delete files.

T1082
System Information Discovery
MalwareAmadey

Amadey has collected the computer name and OS version from a compromised machine.

T1082
System Information Discovery
MalwareSDBbot

SDBbot has the ability to identify the OS version, OS bit information and computer name.

T1083
File and Directory Discovery
MalwareAmadey

Amadey has searched for folders associated with antivirus software.

T1105
Ingress Tool Transfer
MalwareFlawedAmmyy

FlawedAmmyy can transfer files from C2.

T1106
Native API
GroupTA505

TA505 has deployed payloads that use Windows API calls on a compromised host.

T1112
Modify Registry
GroupTA505

TA505 has used malware to disable Windows Defender through modification of the Registry.

T1113
Screen Capture
MalwareFlawedAmmyy

FlawedAmmyy can capture screenshots.

T1115
Clipboard Data
MalwareFlawedAmmyy

FlawedAmmyy can collect clipboard data.

T1140
Deobfuscate/Decode Files or Information
MalwareAmadey

Amadey has decoded antivirus name strings.

T1218.007
Msiexec
MalwareFlawedAmmyy

FlawedAmmyy has been installed via `msiexec.exe`.

T1218.011
Rundll32
MalwareFlawedAmmyy

FlawedAmmyy has used `rundll32` for execution.

T1218.011
Rundll32
MalwareSDBbot

SDBbot has used rundll32.exe to execute DLLs.

T1518.001
Security Software Discovery
MalwareAmadey

Amadey has checked for a variety of antivirus products.

T1547.001
Registry Run Keys / Startup Folder
MalwareAmadey

Amadey has changed the Startup folder to the one containing its executable by overwriting the registry keys.

T1547.001
Registry Run Keys / Startup Folder
MalwareFlawedAmmyy

FlawedAmmyy has established persistence via the `HKCU\SOFTWARE\microsoft\windows\currentversion\run` registry key.

T1553.005
Mark-of-the-Web Bypass
MalwareAmadey

Amadey has modified the `:Zone.Identifier` in the ADS area to zero.

T1568.001
Fast Flux DNS
MalwareAmadey

Amadey has used fast flux DNS for its C2.

T1583.001
Domains
GroupTA505

TA505 has registered domains to impersonate services such as Dropbox to distribute malware.

T1608.001
Upload Malware
GroupTA505

TA505 has staged malware on actor-controlled domains.

T1614
System Location Discovery
MalwareSDBbot

SDBbot can collected the country code of a compromised machine.

T1685
Disable or Modify Tools
GroupTA505

TA505 has used malware to disable Windows Defender.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.