Counter Threat Unit Research Team . (2022, June 23). BRONZE STARLIGHT RANSOMWARE OPERATIONS USE HUI LOADER. Retrieved December 7, 2023.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1140 Deobfuscate/Decode Files or Information |
MalwareHUI Loader | HUI Loader can decrypt and load files containing malicious payloads. |
| T1190 Exploit Public-Facing Application |
GroupCinnamon Tempest | Cinnamon Tempest has exploited multiple unpatched vulnerabilities for initial access including vulnerabilities in Microsoft Exchange, Manage Engine AdSelfService Plus, Confluence, and Log4j. |
| T1574.001 DLL |
GroupCinnamon Tempest | Cinnamon Tempest has used search order hijacking to launch Cobalt Strike Beacons. Cinnamon Tempest has also abused legitimate executables to side-load weaponized DLLs. |
| T1574.001 DLL |
MalwareHUI Loader | HUI Loader can be deployed to targeted systems via legitimate programs that are vulnerable to DLL search order hijacking. |
| T1588.002 Tool |
GroupCinnamon Tempest | Cinnamon Tempest has used open-source tools including customized versions of the Iox proxy tool, NPS tunneling tool, Meterpreter, and a keylogger that uploads data to Alibaba cloud storage. |
| T1685 Disable or Modify Tools |
MalwareHUI Loader | HUI Loader has the ability to disable Windows Event Tracing for Windows (ETW) and Antimalware Scan Interface (AMSI) functions. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.