ATT&CKReferencesCybersecurity Advisory SVR TTP May 2021

Cybersecurity Advisory SVR TTP May 2021

NCSC, CISA, FBI, NSA. (2021, May 7). Further TTPs associated with SVR cyber actors. Retrieved July 29, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples14

TechniqueUsed byProcedure example
T1059.005
Visual Basic
CampaignSolarWinds Compromise

For the SolarWinds Compromise, APT29 wrote malware such as Sibot in Visual Basic.

T1071.001
Web Protocols
ToolSliver

Sliver has the ability to support C2 communications over HTTP and HTTPS.

T1071.004
DNS
ToolSliver

Sliver can support C2 communications over DNS.

T1078
Valid Accounts
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used different compromised credentials for remote access and to move laterally.

T1114.002
Remote Email Collection
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 collected emails from specific individuals, such as executives and IT staff, using `New-MailboxExportRequest` followed by `Get-MailboxExportRequest`.

T1190
Exploit Public-Facing Application
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 exploited CVE-2020-0688 against the Microsoft Exchange Control Panel to regain access to a network.

T1190
Exploit Public-Facing Application
GroupAPT29

APT29 has exploited CVE-2019-19781 for Citrix, CVE-2019-11510 for Pulse Secure VPNs, CVE-2018-13379 for FortiGate VPNs, and CVE-2019-9670 in Zimbra software to gain access.

T1195.002
Compromise Software Supply Chain
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 gained initial network access to some victims via a trojanized update of SolarWinds Orion software.

T1199
Trusted Relationship
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 gained access through compromised accounts at cloud solution partners, and used compromised certificates issued by Mimecast to authenticate to Mimecast customer systems.

T1203
Exploitation for Client Execution
GroupAPT29

APT29 has used multiple software exploits for common client software, like Microsoft Word, Exchange, and Adobe Reader, to gain code execution.

T1505.003
Web Shell
GroupAPT29

APT29 has installed web shells on exploited Microsoft Exchange servers.

T1552.004
Private Keys
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 obtained PKI keys, certificate files, and the private encryption key from an Active Directory Federation Services (AD FS) container to decrypt corresponding SAML signing certificates.

T1573.002
Asymmetric Cryptography
ToolSliver

Sliver can use mutual TLS and RSA cryptography to exchange a session key.

T1595.002
Vulnerability Scanning
GroupAPT29

APT29 has conducted widespread scanning of target environments to identify vulnerabilities for exploit.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.