ATT&CKReferencesSecurelist DarkVishnya Dec 2018

Securelist DarkVishnya Dec 2018

Golovanov, S. (2018, December 6). DarkVishnya: Banks attacked through direct connection to local network. Retrieved May 15, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples10

TechniqueUsed byProcedure example
T1040
Network Sniffing
GroupDarkVishnya

DarkVishnya used network sniffing to obtain login data.

T1046
Network Service Discovery
GroupDarkVishnya

DarkVishnya performed port scanning to obtain the list of active services.

T1059.001
PowerShell
GroupDarkVishnya

DarkVishnya used PowerShell to create shellcode loaders.

T1110
Brute Force
GroupDarkVishnya

DarkVishnya used brute-force attack to obtain login data.

T1135
Network Share Discovery
GroupDarkVishnya

DarkVishnya scanned the network for public shared folders.

T1200
Hardware Additions
GroupDarkVishnya

DarkVishnya physically connected Bash Bunny, Raspberry Pi, netbooks, and inexpensive laptops to the target organization's environment to access the company’s local network.

T1219
Remote Access Tools
GroupDarkVishnya

DarkVishnya used DameWare Mini Remote Control for lateral movement.

T1543.003
Windows Service
GroupDarkVishnya

DarkVishnya created new services for shellcode loaders distribution.

T1571
Non-Standard Port
GroupDarkVishnya

DarkVishnya used ports 5190 and 7900 for shellcode listeners, and 4444, 4445, 31337 for shellcode C2.

T1588.002
Tool
GroupDarkVishnya

DarkVishnya has obtained and used tools such as Impacket, Winexe, and PsExec.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.