ATT&CKReferencesCISA GRU29155 2024

CISA GRU29155 2024

US Cybersecurity & Infrastructure Security Agency et al. (2024, September 5). Russian Military Cyber Actors Target U.S. and Global Critical Infrastructure. Retrieved September 6, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples35

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupEmber Bear

Ember Bear uses legitimate Sysinternals tools such as procdump to dump LSASS memory.

T1003.002
Security Account Manager
GroupEmber Bear

Ember Bear acquires victim credentials by extracting registry hives such as the Security Account Manager through commands such as reg save.

T1003.004
LSA Secrets
GroupEmber Bear

Ember Bear has used frameworks such as Impacket to dump LSA secrets for credential capture.

T1005
Data from Local System
GroupEmber Bear

Ember Bear gathers victim system information such as enumerating the volume of a given device or extracting system and security event logs for analysis.

T1018
Remote System Discovery
GroupEmber Bear

Ember Bear has used tools such as Nmap and MASSCAN for remote service discovery.

T1036.005
Match Legitimate Resource Name or Location
GroupEmber Bear

Ember Bear has renamed tools to match legitimate utilities, such as renaming GOST tunneling instances to `java` in victim environments.

T1046
Network Service Discovery
GroupEmber Bear

Ember Bear has used tools such as NMAP for remote system discovery and enumeration in victim environments.

T1047
Windows Management Instrumentation
GroupEmber Bear

Ember Bear has used WMI execution with password hashes for command execution and lateral movement.

T1059.001
PowerShell
GroupEmber Bear

Ember Bear has used PowerShell commands to gather information from compromised systems, such as email servers.

T1071.004
DNS
GroupEmber Bear

Ember Bear has used DNS tunnelling tools, such as dnscat/2 and Iodine, for C2 purposes.

T1078.001
Default Accounts
GroupEmber Bear

Ember Bear has abused default user names and passwords in externally-accessible IP cameras for initial access.

T1090.003
Multi-hop Proxy
GroupEmber Bear

Ember Bear has configured multi-hop proxies via ProxyChains within victim environments.

T1095
Non-Application Layer Protocol
GroupEmber Bear

Ember Bear uses socket-based tunneling utilities for command and control purposes such as NetCat and Go Simple Tunnel (GOST). These tunnels are used to push interactive command prompts over the created sockets. Ember Bear has also used reverse TCP connections from Meterpreter installations to communicate back with C2 infrastructure.

T1110
Brute Force
GroupEmber Bear

Ember Bear used the `su-bruteforce` tool to brute force specific users using the `su` command.

T1110.003
Password Spraying
GroupEmber Bear

Ember Bear has conducted password spraying against Outlook Web Access (OWA) infrastructure to identify valid user names and passwords.

T1114
Email Collection
GroupEmber Bear

Ember Bear attempts to collect mail from accessed systems and servers.

T1125
Video Capture
GroupEmber Bear

Ember Bear has exfiltrated images from compromised IP cameras.

T1133
External Remote Services
GroupEmber Bear

Ember Bear have used VPNs both for initial access to victim environments and for persistence within them following compromise.

T1190
Exploit Public-Facing Application
GroupEmber Bear

Ember Bear gains initial access to victim environments by exploiting external-facing services. Examples include exploitation of CVE-2021-26084 in Confluence servers; CVE-2022-41040, ProxyShell, and other vulnerabilities in Microsoft Exchange; and multiple vulnerabilities in open-source platforms such as content management systems.

T1203
Exploitation for Client Execution
GroupEmber Bear

Ember Bear has used exploits to enable follow-on execution of frameworks such as Meterpreter.

T1210
Exploitation of Remote Services
GroupEmber Bear

Ember Bear has used exploits for vulnerabilities such as MS17-010, also known as `Eternal Blue`, during operations.

T1505.003
Web Shell
GroupEmber Bear

Ember Bear deploys web shells following initial access for either follow-on command execution or protocol tunneling. Example web shells used by Ember Bear include P0wnyshell, reGeorg, P.A.S. Webshell, and custom variants of publicly-available web shell examples.

T1550.002
Pass the Hash
GroupEmber Bear

Ember Bear has used pass-the-hash techniques for lateral movement in victim environments.

T1552.001
Credentials In Files
GroupEmber Bear

Ember Bear has dumped configuration settings in accessed IP cameras including plaintext credentials.

T1560
Archive Collected Data
GroupEmber Bear

Ember Bear has compressed collected data prior to exfiltration.

T1567.002
Exfiltration to Cloud Storage
GroupEmber Bear

Ember Bear has used tools such as Rclone to exfiltrate information from victim environments to cloud storage such as `mega.nz`.

T1571
Non-Standard Port
GroupEmber Bear

Ember Bear has used various non-standard ports for C2 communication.

T1572
Protocol Tunneling
GroupEmber Bear

Ember Bear has used ProxyChains to tunnel protocols to internal networks.

T1583.003
Virtual Private Server
GroupEmber Bear

Ember Bear has used virtual private servers (VPSs) to host tools, perform reconnaissance, exploit victim infrastructure, and as a destination for data exfiltration.

T1585
Establish Accounts
GroupEmber Bear

Ember Bear has created accounts on dark web forums to obtain various tools and malware.

T1588.001
Malware
GroupEmber Bear

Ember Bear has acquired malware and related tools from dark web forums.

T1588.005
Exploits
GroupEmber Bear

Ember Bear has obtained exploitation scripts against publicly-disclosed vulnerabilities from public repositories.

T1595.001
Scanning IP Blocks
GroupEmber Bear

Ember Bear has targeted IP ranges for vulnerability scanning related to government and critical infrastructure organizations.

T1595.002
Vulnerability Scanning
GroupEmber Bear

Ember Bear has used publicly available tools such as MASSCAN and Acunetix for vulnerability scanning of public-facing infrastructure.

T1654
Log Enumeration
GroupEmber Bear

Ember Bear has enumerated SECURITY and SYSTEM log files during intrusions.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.