US Cybersecurity & Infrastructure Security Agency et al. (2024, September 5). Russian Military Cyber Actors Target U.S. and Global Critical Infrastructure. Retrieved September 6, 2024.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupEmber Bear | Ember Bear uses legitimate Sysinternals tools such as procdump to dump LSASS memory. |
| T1003.002 Security Account Manager |
GroupEmber Bear | Ember Bear acquires victim credentials by extracting registry hives such as the Security Account Manager through commands such as |
| T1003.004 LSA Secrets |
GroupEmber Bear | Ember Bear has used frameworks such as Impacket to dump LSA secrets for credential capture. |
| T1005 Data from Local System |
GroupEmber Bear | Ember Bear gathers victim system information such as enumerating the volume of a given device or extracting system and security event logs for analysis. |
| T1018 Remote System Discovery |
GroupEmber Bear | Ember Bear has used tools such as Nmap and MASSCAN for remote service discovery. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupEmber Bear | Ember Bear has renamed tools to match legitimate utilities, such as renaming GOST tunneling instances to `java` in victim environments. |
| T1046 Network Service Discovery |
GroupEmber Bear | Ember Bear has used tools such as NMAP for remote system discovery and enumeration in victim environments. |
| T1047 Windows Management Instrumentation |
GroupEmber Bear | Ember Bear has used WMI execution with password hashes for command execution and lateral movement. |
| T1059.001 PowerShell |
GroupEmber Bear | Ember Bear has used PowerShell commands to gather information from compromised systems, such as email servers. |
| T1071.004 DNS |
GroupEmber Bear | Ember Bear has used DNS tunnelling tools, such as dnscat/2 and Iodine, for C2 purposes. |
| T1078.001 Default Accounts |
GroupEmber Bear | Ember Bear has abused default user names and passwords in externally-accessible IP cameras for initial access. |
| T1090.003 Multi-hop Proxy |
GroupEmber Bear | Ember Bear has configured multi-hop proxies via ProxyChains within victim environments. |
| T1095 Non-Application Layer Protocol |
GroupEmber Bear | Ember Bear uses socket-based tunneling utilities for command and control purposes such as NetCat and Go Simple Tunnel (GOST). These tunnels are used to push interactive command prompts over the created sockets. Ember Bear has also used reverse TCP connections from Meterpreter installations to communicate back with C2 infrastructure. |
| T1110 Brute Force |
GroupEmber Bear | Ember Bear used the `su-bruteforce` tool to brute force specific users using the `su` command. |
| T1110.003 Password Spraying |
GroupEmber Bear | Ember Bear has conducted password spraying against Outlook Web Access (OWA) infrastructure to identify valid user names and passwords. |
| T1114 Email Collection |
GroupEmber Bear | Ember Bear attempts to collect mail from accessed systems and servers. |
| T1125 Video Capture |
GroupEmber Bear | Ember Bear has exfiltrated images from compromised IP cameras. |
| T1133 External Remote Services |
GroupEmber Bear | Ember Bear have used VPNs both for initial access to victim environments and for persistence within them following compromise. |
| T1190 Exploit Public-Facing Application |
GroupEmber Bear | Ember Bear gains initial access to victim environments by exploiting external-facing services. Examples include exploitation of CVE-2021-26084 in Confluence servers; CVE-2022-41040, ProxyShell, and other vulnerabilities in Microsoft Exchange; and multiple vulnerabilities in open-source platforms such as content management systems. |
| T1203 Exploitation for Client Execution |
GroupEmber Bear | Ember Bear has used exploits to enable follow-on execution of frameworks such as Meterpreter. |
| T1210 Exploitation of Remote Services |
GroupEmber Bear | Ember Bear has used exploits for vulnerabilities such as MS17-010, also known as `Eternal Blue`, during operations. |
| T1505.003 Web Shell |
GroupEmber Bear | Ember Bear deploys web shells following initial access for either follow-on command execution or protocol tunneling. Example web shells used by Ember Bear include P0wnyshell, reGeorg, P.A.S. Webshell, and custom variants of publicly-available web shell examples. |
| T1550.002 Pass the Hash |
GroupEmber Bear | Ember Bear has used pass-the-hash techniques for lateral movement in victim environments. |
| T1552.001 Credentials In Files |
GroupEmber Bear | Ember Bear has dumped configuration settings in accessed IP cameras including plaintext credentials. |
| T1560 Archive Collected Data |
GroupEmber Bear | Ember Bear has compressed collected data prior to exfiltration. |
| T1567.002 Exfiltration to Cloud Storage |
GroupEmber Bear | Ember Bear has used tools such as Rclone to exfiltrate information from victim environments to cloud storage such as `mega.nz`. |
| T1571 Non-Standard Port |
GroupEmber Bear | Ember Bear has used various non-standard ports for C2 communication. |
| T1572 Protocol Tunneling |
GroupEmber Bear | Ember Bear has used ProxyChains to tunnel protocols to internal networks. |
| T1583.003 Virtual Private Server |
GroupEmber Bear | Ember Bear has used virtual private servers (VPSs) to host tools, perform reconnaissance, exploit victim infrastructure, and as a destination for data exfiltration. |
| T1585 Establish Accounts |
GroupEmber Bear | Ember Bear has created accounts on dark web forums to obtain various tools and malware. |
| T1588.001 Malware |
GroupEmber Bear | Ember Bear has acquired malware and related tools from dark web forums. |
| T1588.005 Exploits |
GroupEmber Bear | Ember Bear has obtained exploitation scripts against publicly-disclosed vulnerabilities from public repositories. |
| T1595.001 Scanning IP Blocks |
GroupEmber Bear | Ember Bear has targeted IP ranges for vulnerability scanning related to government and critical infrastructure organizations. |
| T1595.002 Vulnerability Scanning |
GroupEmber Bear | Ember Bear has used publicly available tools such as MASSCAN and Acunetix for vulnerability scanning of public-facing infrastructure. |
| T1654 Log Enumeration |
GroupEmber Bear | Ember Bear has enumerated SECURITY and SYSTEM log files during intrusions. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.