NCSC, CISA, FBI, NSA. (2021, May 7). Further TTPs associated with SVR cyber actors. Retrieved July 29, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.005 Visual Basic |
CampaignSolarWinds Compromise | For the SolarWinds Compromise, APT29 wrote malware such as Sibot in Visual Basic. |
| T1071.001 Web Protocols |
ToolSliver | Sliver has the ability to support C2 communications over HTTP and HTTPS. |
| T1071.004 DNS |
ToolSliver | Sliver can support C2 communications over DNS. |
| T1078 Valid Accounts |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used different compromised credentials for remote access and to move laterally. |
| T1114.002 Remote Email Collection |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 collected emails from specific individuals, such as executives and IT staff, using `New-MailboxExportRequest` followed by `Get-MailboxExportRequest`. |
| T1190 Exploit Public-Facing Application |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 exploited CVE-2020-0688 against the Microsoft Exchange Control Panel to regain access to a network. |
| T1190 Exploit Public-Facing Application |
GroupAPT29 | APT29 has exploited CVE-2019-19781 for Citrix, CVE-2019-11510 for Pulse Secure VPNs, CVE-2018-13379 for FortiGate VPNs, and CVE-2019-9670 in Zimbra software to gain access. |
| T1195.002 Compromise Software Supply Chain |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 gained initial network access to some victims via a trojanized update of SolarWinds Orion software. |
| T1199 Trusted Relationship |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 gained access through compromised accounts at cloud solution partners, and used compromised certificates issued by Mimecast to authenticate to Mimecast customer systems. |
| T1203 Exploitation for Client Execution |
GroupAPT29 | APT29 has used multiple software exploits for common client software, like Microsoft Word, Exchange, and Adobe Reader, to gain code execution. |
| T1505.003 Web Shell |
GroupAPT29 | APT29 has installed web shells on exploited Microsoft Exchange servers. |
| T1552.004 Private Keys |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 obtained PKI keys, certificate files, and the private encryption key from an Active Directory Federation Services (AD FS) container to decrypt corresponding SAML signing certificates. |
| T1573.002 Asymmetric Cryptography |
ToolSliver | Sliver can use mutual TLS and RSA cryptography to exchange a session key. |
| T1595.002 Vulnerability Scanning |
GroupAPT29 | APT29 has conducted widespread scanning of target environments to identify vulnerabilities for exploit. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.