ESET. (2016, October). En Route with Sednit - Part 2: Observing the Comings and Goings. Retrieved November 21, 2016.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003 OS Credential Dumping |
GroupAPT28 | APT28 regularly deploys both publicly available (ex: Mimikatz) and custom password retrieval tools on victims. |
| T1003.001 LSASS Memory |
GroupAPT28 | APT28 regularly deploys both publicly available (ex: Mimikatz) and custom password retrieval tools on victims. They have also dumped the LSASS process memory using the MiniDump function. |
| T1008 Fallback Channels |
MalwareCHOPSTICK | CHOPSTICK can switch to a new C2 channel if the current one is broken. |
| T1008 Fallback Channels |
MalwareXTunnel | The C2 server used by XTunnel provides a port number to the victim to use as a fallback in case the connection closes on the currently used port. |
| T1012 Query Registry |
MalwareADVSTORESHELL | ADVSTORESHELL can enumerate registry keys. |
| T1027 Obfuscated Files or Information |
MalwareXTunnel | A version of XTunnel introduced in July 2015 obfuscated the binary using opaque predicates and other techniques in a likely attempt to obfuscate it and bypass security products. |
| T1027.016 Junk Code Insertion |
MalwareXTunnel | A version of XTunnel introduced in July 2015 inserted junk code into the binary in a likely attempt to obfuscate it and bypass security products. |
| T1029 Scheduled Transfer |
MalwareADVSTORESHELL | ADVSTORESHELL collects, compresses, encrypts, and exfiltrates data to the C2 server every 10 minutes. |
| T1041 Exfiltration Over C2 Channel |
MalwareADVSTORESHELL | ADVSTORESHELL exfiltrates data over the same channel used for C2. |
| T1056.001 Keylogging |
MalwareCHOPSTICK | CHOPSTICK is capable of performing keylogging. |
| T1056.001 Keylogging |
MalwareADVSTORESHELL | ADVSTORESHELL can perform keylogging. |
| T1057 Process Discovery |
MalwareADVSTORESHELL | ADVSTORESHELL can list running processes. |
| T1059 Command and Scripting Interpreter |
MalwareCHOPSTICK | CHOPSTICK is capable of performing remote command execution. |
| T1059.003 Windows Command Shell |
MalwareADVSTORESHELL | ADVSTORESHELL can create a remote shell and run a given command. |
| T1070.004 File Deletion |
MalwareADVSTORESHELL | ADVSTORESHELL can delete files and directories. |
| T1071.001 Web Protocols |
MalwareCHOPSTICK | Various implementations of CHOPSTICK communicate with C2 over HTTP. |
| T1071.003 Mail Protocols |
MalwareCHOPSTICK | Various implementations of CHOPSTICK communicate with C2 over SMTP and POP3. |
| T1074.001 Local Data Staging |
MalwareADVSTORESHELL | ADVSTORESHELL stores output from command execution in a .dat file in the %TEMP% directory. |
| T1082 System Information Discovery |
MalwareADVSTORESHELL | ADVSTORESHELL can run Systeminfo to gather information about the victim. |
| T1083 File and Directory Discovery |
MalwareADVSTORESHELL | ADVSTORESHELL can list files and directories. |
| T1083 File and Directory Discovery |
MalwareCHOPSTICK | An older version of CHOPSTICK has a module that monitors all mounted volumes for files with the extensions .doc, .docx, .pgp, .gpg, .m2f, or .m2o. |
| T1090.001 Internal Proxy |
MalwareCHOPSTICK | CHOPSTICK used a proxy server between victims and the C2 server. |
| T1092 Communication Through Removable Media |
MalwareCHOPSTICK | Part of APT28's operation involved using CHOPSTICK modules to copy itself to air-gapped machines, using files written to USB sticks to transfer data and command traffic. |
| T1113 Screen Capture |
GroupAPT28 | APT28 has used tools to take screenshots from victims. |
| T1120 Peripheral Device Discovery |
MalwareADVSTORESHELL | ADVSTORESHELL can list connected devices. |
| T1546.015 Component Object Model Hijacking |
MalwareADVSTORESHELL | Some variants of ADVSTORESHELL achieve persistence by registering the payload as a Shell Icon Overlay handler COM object. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareADVSTORESHELL | ADVSTORESHELL achieves persistence by adding itself to the |
| T1560 Archive Collected Data |
MalwareADVSTORESHELL | ADVSTORESHELL encrypts with the 3DES algorithm and a hardcoded key prior to exfiltration. |
| T1560.003 Archive via Custom Method |
MalwareADVSTORESHELL | ADVSTORESHELL compresses output data generated by command execution with a custom implementation of the Lempel–Ziv–Welch (LZW) algorithm. |
| T1573.001 Symmetric Cryptography |
MalwareCHOPSTICK | CHOPSTICK encrypts C2 communications with RC4. |
| T1573.002 Asymmetric Cryptography |
MalwareCHOPSTICK | CHOPSTICK encrypts C2 communications with TLS. |
| T1573.002 Asymmetric Cryptography |
MalwareXTunnel | XTunnel uses SSL/TLS and RC4 to encrypt traffic. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.