Nafisi, R., Lelli, A. (2021, March 4). GoldMax, GoldFinder, and Sibot: Analyzing NOBELIUM’s layered persistence. Retrieved March 8, 2021.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1001.001 Junk Data |
MalwareGoldMax | GoldMax has used decoy traffic to surround its malicious network traffic to avoid detection. |
| T1012 Query Registry |
MalwareSibot | Sibot has queried the registry for proxy server information. |
| T1016 System Network Configuration Discovery |
MalwareSibot | Sibot checked if the compromised system is configured to use proxies. |
| T1016 System Network Configuration Discovery |
MalwareGoldMax | GoldMax retrieved a list of the system's network interface after execution. |
| T1016.001 Internet Connection Discovery |
MalwareGoldFinder | GoldFinder performed HTTP GET requests to check internet connectivity and identify HTTP proxy servers and other redirectors that an HTTP request traveled through. |
| T1016.001 Internet Connection Discovery |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used GoldFinder to perform HTTP GET requests to check internet connectivity and identify HTTP proxy servers and other redirectors that an HTTP request travels through. |
| T1027.010 Command Obfuscation |
MalwareSibot | Sibot has obfuscated scripts used in execution. |
| T1027.011 Fileless Storage |
MalwareSibot | Sibot has installed a second-stage script in the |
| T1027.013 Encrypted/Encoded File |
MalwareGoldMax | GoldMax has written AES-encrypted and Base64-encoded configuration files to disk. |
| T1036.004 Masquerade Task or Service |
MalwareGoldMax | GoldMax has impersonated systems management software to avoid detection. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareGoldMax | GoldMax has used filenames that matched the system name, and appeared as a scheduled task impersonating systems management software within the corresponding ProgramData subfolder. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareSibot | Sibot has downloaded a DLL to the |
| T1041 Exfiltration Over C2 Channel |
MalwareGoldMax | GoldMax can exfiltrate files over the existing C2 channel. |
| T1047 Windows Management Instrumentation |
MalwareSibot | Sibot has used WMI to discover network connections and configurations. Sibot has also used the Win32_Process class to execute a malicious DLL. |
| T1049 System Network Connections Discovery |
MalwareSibot | Sibot has retrieved a GUID associated with a present LAN connection on a compromised machine. |
| T1053.005 Scheduled Task |
MalwareSibot | Sibot has been executed via a scheduled task. |
| T1053.005 Scheduled Task |
MalwareGoldMax | GoldMax has used scheduled tasks to maintain persistence. |
| T1059.003 Windows Command Shell |
MalwareGoldMax | GoldMax can spawn a command shell, and execute native commands. |
| T1059.005 Visual Basic |
MalwareSibot | Sibot executes commands using VBScript. |
| T1070 Indicator Removal |
MalwareSibot | Sibot will delete an associated registry key if a certain server response is received. |
| T1070.004 File Deletion |
MalwareSibot | Sibot will delete itself if a certain server response is received. |
| T1071.001 Web Protocols |
MalwareGoldMax | GoldMax has used HTTPS and HTTP GET requests with custom HTTP cookies for C2. |
| T1071.001 Web Protocols |
MalwareGoldFinder | GoldFinder has used HTTP for C2. |
| T1071.001 Web Protocols |
MalwareSibot | Sibot communicated with its C2 server via HTTP GET requests. |
| T1078 Valid Accounts |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used different compromised credentials for remote access and to move laterally. |
| T1102 Web Service |
MalwareSibot | Sibot has used a legitimate compromised website to download DLLs to the victim's machine. |
| T1105 Ingress Tool Transfer |
MalwareSibot | Sibot can download and execute a payload onto a compromised system. |
| T1105 Ingress Tool Transfer |
MalwareGoldMax | GoldMax can download and execute additional files. |
| T1112 Modify Registry |
MalwareSibot | Sibot has modified the Registry to install a second-stage script in the |
| T1119 Automated Collection |
MalwareGoldFinder | GoldFinder logged and stored information related to the route or hops a packet took from a compromised machine to a hardcoded C2 server, including the target C2 URL, HTTP response/status code, HTTP response headers and values, and data received from the C2 node. |
| T1124 System Time Discovery |
MalwareGoldMax | GoldMax can check the current date-time value of the compromised system, comparing it to the hardcoded execution trigger and can send the current timestamp to the C2 server. |
| T1133 External Remote Services |
CampaignSolarWinds Compromise | For the SolarWinds Compromise, APT29 used compromised identities to access networks via SSH, VPNs, and other remote access tools. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareSibot | Sibot can decrypt data received from a C2 and save to a file. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareGoldMax | GoldMax has decoded and decrypted the configuration file when executed. |
| T1218.005 Mshta |
MalwareSibot | Sibot has been executed via MSHTA application. |
| T1218.011 Rundll32 |
MalwareSibot | Sibot has executed downloaded DLLs with |
| T1497.001 System Checks |
MalwareGoldMax | GoldMax will check if it is being run in a virtualized environment by comparing the collected MAC address to |
| T1497.003 Time Based Checks |
MalwareGoldMax | GoldMax has set an execution trigger date and time, stored as an ASCII Unix/Epoch time value. |
| T1573.002 Asymmetric Cryptography |
MalwareGoldMax | GoldMax has RSA-encrypted its communication with the C2 server. |
| T1583.001 Domains |
CampaignSolarWinds Compromise | For the SolarWinds Compromise, APT29 acquired C2 domains, sometimes through resellers. |
| T1584.001 Domains |
CampaignSolarWinds Compromise | For the SolarWinds Compromise, APT29 compromised domains to use for C2. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.