ATT&CKReferencesSecureworks BRONZE BUTLER Oct 2017

Secureworks BRONZE BUTLER Oct 2017

Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples34

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupBRONZE BUTLER

BRONZE BUTLER has used various tools (such as Mimikatz and WCE) to perform credential dumping.

T1005
Data from Local System
GroupBRONZE BUTLER

BRONZE BUTLER has exfiltrated files stolen from local systems.

T1018
Remote System Discovery
GroupBRONZE BUTLER

BRONZE BUTLER typically use ping and Net to enumerate systems.

T1027.001
Binary Padding
GroupBRONZE BUTLER

BRONZE BUTLER downloader code has included "0" characters at the end of the file to inflate the file size in a likely attempt to evade anti-virus detection.

T1036.005
Match Legitimate Resource Name or Location
GroupBRONZE BUTLER

BRONZE BUTLER has given malware the same name as an existing file on the file share server to cause users to unwittingly launch and install the malware on additional systems.

T1039
Data from Network Shared Drive
GroupBRONZE BUTLER

BRONZE BUTLER has exfiltrated files stolen from file shares.

T1053.002
At
GroupBRONZE BUTLER

BRONZE BUTLER has used at to register a scheduled task to execute malware during lateral movement.

T1053.005
Scheduled Task
GroupBRONZE BUTLER

BRONZE BUTLER has used schtasks to register a scheduled task to execute malware during lateral movement.

T1056.001
Keylogging
MalwareDaserf

Daserf can log keystrokes.

T1059.001
PowerShell
GroupBRONZE BUTLER

BRONZE BUTLER has used PowerShell for execution.

T1059.003
Windows Command Shell
GroupBRONZE BUTLER

BRONZE BUTLER has used batch scripts and the command-line interface for execution.

T1059.003
Windows Command Shell
MalwareDaserf

Daserf can execute shell commands.

T1059.005
Visual Basic
GroupBRONZE BUTLER

BRONZE BUTLER has used VBS and VBE scripts for execution.

T1070.004
File Deletion
GroupBRONZE BUTLER

The BRONZE BUTLER uploader or malware the uploader uses command to delete the RAR archives after they have been exfiltrated.

T1071.001
Web Protocols
MalwareDaserf

Daserf uses HTTP for C2.

T1071.001
Web Protocols
GroupBRONZE BUTLER

BRONZE BUTLER malware has used HTTP for C2.

T1080
Taint Shared Content
GroupBRONZE BUTLER

BRONZE BUTLER has placed malware on file shares and given it the same name as legitimate documents on the share.

T1083
File and Directory Discovery
GroupBRONZE BUTLER

BRONZE BUTLER has collected a list of files from the victim and uploaded it to its C2 server, and then created a new list of specific files to steal.

T1087.002
Domain Account
GroupBRONZE BUTLER

BRONZE BUTLER has used net user /domain to identify account information.

T1102.001
Dead Drop Resolver
GroupBRONZE BUTLER

BRONZE BUTLER's MSGET downloader uses a dead drop resolver to access malicious payloads.

T1105
Ingress Tool Transfer
MalwareDaserf

Daserf can download remote files.

T1105
Ingress Tool Transfer
GroupBRONZE BUTLER

BRONZE BUTLER has used various tools to download files, including DGet (a similar tool to wget).

T1113
Screen Capture
GroupBRONZE BUTLER

BRONZE BUTLER has used a tool to capture screenshots.

T1113
Screen Capture
MalwareDaserf

Daserf can take screenshots.

T1124
System Time Discovery
GroupBRONZE BUTLER

BRONZE BUTLER has used net time to check the local time on a target system.

T1132.001
Standard Encoding
MalwareDaserf

Daserf uses custom base64 encoding to obfuscate HTTP traffic.

T1132.001
Standard Encoding
GroupBRONZE BUTLER

Several BRONZE BUTLER tools encode data with base64 when posting it to a C2 server.

T1140
Deobfuscate/Decode Files or Information
GroupBRONZE BUTLER

BRONZE BUTLER downloads encoded payloads and decodes them on the victim.

T1547.001
Registry Run Keys / Startup Folder
GroupBRONZE BUTLER

BRONZE BUTLER has used a batch script that adds a Registry Run key to establish malware persistence.

T1548.002
Bypass User Account Control
GroupBRONZE BUTLER

BRONZE BUTLER has used a Windows 10 specific tool and xxmm to bypass UAC for privilege escalation.

T1550.003
Pass the Ticket
GroupBRONZE BUTLER

BRONZE BUTLER has created forged Kerberos Ticket Granting Ticket (TGT) and Ticket Granting Service (TGS) tickets to maintain administrative access.

T1560.001
Archive via Utility
GroupBRONZE BUTLER

BRONZE BUTLER has compressed data into password-protected RAR archives prior to exfiltration.

T1573.001
Symmetric Cryptography
GroupBRONZE BUTLER

BRONZE BUTLER has used RC4 encryption (for Datper malware) and AES (for xxmm malware) to obfuscate HTTP traffic. BRONZE BUTLER has also used a tool called RarStar that encodes data with a custom XOR algorithm when posting it to a C2 server.

T1573.001
Symmetric Cryptography
MalwareDaserf

Daserf uses RC4 encryption to obfuscate HTTP traffic.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.