ATT&CKReferencesMSTIC NOBELIUM Mar 2021

MSTIC NOBELIUM Mar 2021

Nafisi, R., Lelli, A. (2021, March 4). GoldMax, GoldFinder, and Sibot: Analyzing NOBELIUM’s layered persistence. Retrieved March 8, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software3

Campaigns0

None recorded.

Procedure examples41

TechniqueUsed byProcedure example
T1001.001
Junk Data
MalwareGoldMax

GoldMax has used decoy traffic to surround its malicious network traffic to avoid detection.

T1012
Query Registry
MalwareSibot

Sibot has queried the registry for proxy server information.

T1016
System Network Configuration Discovery
MalwareSibot

Sibot checked if the compromised system is configured to use proxies.

T1016
System Network Configuration Discovery
MalwareGoldMax

GoldMax retrieved a list of the system's network interface after execution.

T1016.001
Internet Connection Discovery
MalwareGoldFinder

GoldFinder performed HTTP GET requests to check internet connectivity and identify HTTP proxy servers and other redirectors that an HTTP request traveled through.

T1016.001
Internet Connection Discovery
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used GoldFinder to perform HTTP GET requests to check internet connectivity and identify HTTP proxy servers and other redirectors that an HTTP request travels through.

T1027.010
Command Obfuscation
MalwareSibot

Sibot has obfuscated scripts used in execution.

T1027.011
Fileless Storage
MalwareSibot

Sibot has installed a second-stage script in the HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\sibot registry key.

T1027.013
Encrypted/Encoded File
MalwareGoldMax

GoldMax has written AES-encrypted and Base64-encoded configuration files to disk.

T1036.004
Masquerade Task or Service
MalwareGoldMax

GoldMax has impersonated systems management software to avoid detection.

T1036.005
Match Legitimate Resource Name or Location
MalwareGoldMax

GoldMax has used filenames that matched the system name, and appeared as a scheduled task impersonating systems management software within the corresponding ProgramData subfolder.

T1036.005
Match Legitimate Resource Name or Location
MalwareSibot

Sibot has downloaded a DLL to the C:\windows\system32\drivers\ folder and renamed it with a .sys extension.

T1041
Exfiltration Over C2 Channel
MalwareGoldMax

GoldMax can exfiltrate files over the existing C2 channel.

T1047
Windows Management Instrumentation
MalwareSibot

Sibot has used WMI to discover network connections and configurations. Sibot has also used the Win32_Process class to execute a malicious DLL.

T1049
System Network Connections Discovery
MalwareSibot

Sibot has retrieved a GUID associated with a present LAN connection on a compromised machine.

T1053.005
Scheduled Task
MalwareSibot

Sibot has been executed via a scheduled task.

T1053.005
Scheduled Task
MalwareGoldMax

GoldMax has used scheduled tasks to maintain persistence.

T1059.003
Windows Command Shell
MalwareGoldMax

GoldMax can spawn a command shell, and execute native commands.

T1059.005
Visual Basic
MalwareSibot

Sibot executes commands using VBScript.

T1070
Indicator Removal
MalwareSibot

Sibot will delete an associated registry key if a certain server response is received.

T1070.004
File Deletion
MalwareSibot

Sibot will delete itself if a certain server response is received.

T1071.001
Web Protocols
MalwareGoldMax

GoldMax has used HTTPS and HTTP GET requests with custom HTTP cookies for C2.

T1071.001
Web Protocols
MalwareGoldFinder

GoldFinder has used HTTP for C2.

T1071.001
Web Protocols
MalwareSibot

Sibot communicated with its C2 server via HTTP GET requests.

T1078
Valid Accounts
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used different compromised credentials for remote access and to move laterally.

T1102
Web Service
MalwareSibot

Sibot has used a legitimate compromised website to download DLLs to the victim's machine.

T1105
Ingress Tool Transfer
MalwareSibot

Sibot can download and execute a payload onto a compromised system.

T1105
Ingress Tool Transfer
MalwareGoldMax

GoldMax can download and execute additional files.

T1112
Modify Registry
MalwareSibot

Sibot has modified the Registry to install a second-stage script in the HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\sibot.

T1119
Automated Collection
MalwareGoldFinder

GoldFinder logged and stored information related to the route or hops a packet took from a compromised machine to a hardcoded C2 server, including the target C2 URL, HTTP response/status code, HTTP response headers and values, and data received from the C2 node.

T1124
System Time Discovery
MalwareGoldMax

GoldMax can check the current date-time value of the compromised system, comparing it to the hardcoded execution trigger and can send the current timestamp to the C2 server.

T1133
External Remote Services
CampaignSolarWinds Compromise

For the SolarWinds Compromise, APT29 used compromised identities to access networks via SSH, VPNs, and other remote access tools.

T1140
Deobfuscate/Decode Files or Information
MalwareSibot

Sibot can decrypt data received from a C2 and save to a file.

T1140
Deobfuscate/Decode Files or Information
MalwareGoldMax

GoldMax has decoded and decrypted the configuration file when executed.

T1218.005
Mshta
MalwareSibot

Sibot has been executed via MSHTA application.

T1218.011
Rundll32
MalwareSibot

Sibot has executed downloaded DLLs with rundll32.exe.

T1497.001
System Checks
MalwareGoldMax

GoldMax will check if it is being run in a virtualized environment by comparing the collected MAC address to c8:27:cc:c2:37:5a.

T1497.003
Time Based Checks
MalwareGoldMax

GoldMax has set an execution trigger date and time, stored as an ASCII Unix/Epoch time value.

T1573.002
Asymmetric Cryptography
MalwareGoldMax

GoldMax has RSA-encrypted its communication with the C2 server.

T1583.001
Domains
CampaignSolarWinds Compromise

For the SolarWinds Compromise, APT29 acquired C2 domains, sometimes through resellers.

T1584.001
Domains
CampaignSolarWinds Compromise

For the SolarWinds Compromise, APT29 compromised domains to use for C2.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.