ATT&CKReferencesESET Sednit Part 2

ESET Sednit Part 2

ESET. (2016, October). En Route with Sednit - Part 2: Observing the Comings and Goings. Retrieved November 21, 2016.

Open the source

Techniques1

Groups0

None recorded.

Software3

Campaigns0

None recorded.

Procedure examples32

TechniqueUsed byProcedure example
T1003
OS Credential Dumping
GroupAPT28

APT28 regularly deploys both publicly available (ex: Mimikatz) and custom password retrieval tools on victims.

T1003.001
LSASS Memory
GroupAPT28

APT28 regularly deploys both publicly available (ex: Mimikatz) and custom password retrieval tools on victims. They have also dumped the LSASS process memory using the MiniDump function.

T1008
Fallback Channels
MalwareCHOPSTICK

CHOPSTICK can switch to a new C2 channel if the current one is broken.

T1008
Fallback Channels
MalwareXTunnel

The C2 server used by XTunnel provides a port number to the victim to use as a fallback in case the connection closes on the currently used port.

T1012
Query Registry
MalwareADVSTORESHELL

ADVSTORESHELL can enumerate registry keys.

T1027
Obfuscated Files or Information
MalwareXTunnel

A version of XTunnel introduced in July 2015 obfuscated the binary using opaque predicates and other techniques in a likely attempt to obfuscate it and bypass security products.

T1027.016
Junk Code Insertion
MalwareXTunnel

A version of XTunnel introduced in July 2015 inserted junk code into the binary in a likely attempt to obfuscate it and bypass security products.

T1029
Scheduled Transfer
MalwareADVSTORESHELL

ADVSTORESHELL collects, compresses, encrypts, and exfiltrates data to the C2 server every 10 minutes.

T1041
Exfiltration Over C2 Channel
MalwareADVSTORESHELL

ADVSTORESHELL exfiltrates data over the same channel used for C2.

T1056.001
Keylogging
MalwareCHOPSTICK

CHOPSTICK is capable of performing keylogging.

T1056.001
Keylogging
MalwareADVSTORESHELL

ADVSTORESHELL can perform keylogging.

T1057
Process Discovery
MalwareADVSTORESHELL

ADVSTORESHELL can list running processes.

T1059
Command and Scripting Interpreter
MalwareCHOPSTICK

CHOPSTICK is capable of performing remote command execution.

T1059.003
Windows Command Shell
MalwareADVSTORESHELL

ADVSTORESHELL can create a remote shell and run a given command.

T1070.004
File Deletion
MalwareADVSTORESHELL

ADVSTORESHELL can delete files and directories.

T1071.001
Web Protocols
MalwareCHOPSTICK

Various implementations of CHOPSTICK communicate with C2 over HTTP.

T1071.003
Mail Protocols
MalwareCHOPSTICK

Various implementations of CHOPSTICK communicate with C2 over SMTP and POP3.

T1074.001
Local Data Staging
MalwareADVSTORESHELL

ADVSTORESHELL stores output from command execution in a .dat file in the %TEMP% directory.

T1082
System Information Discovery
MalwareADVSTORESHELL

ADVSTORESHELL can run Systeminfo to gather information about the victim.

T1083
File and Directory Discovery
MalwareADVSTORESHELL

ADVSTORESHELL can list files and directories.

T1083
File and Directory Discovery
MalwareCHOPSTICK

An older version of CHOPSTICK has a module that monitors all mounted volumes for files with the extensions .doc, .docx, .pgp, .gpg, .m2f, or .m2o.

T1090.001
Internal Proxy
MalwareCHOPSTICK

CHOPSTICK used a proxy server between victims and the C2 server.

T1092
Communication Through Removable Media
MalwareCHOPSTICK

Part of APT28's operation involved using CHOPSTICK modules to copy itself to air-gapped machines, using files written to USB sticks to transfer data and command traffic.

T1113
Screen Capture
GroupAPT28

APT28 has used tools to take screenshots from victims.

T1120
Peripheral Device Discovery
MalwareADVSTORESHELL

ADVSTORESHELL can list connected devices.

T1546.015
Component Object Model Hijacking
MalwareADVSTORESHELL

Some variants of ADVSTORESHELL achieve persistence by registering the payload as a Shell Icon Overlay handler COM object.

T1547.001
Registry Run Keys / Startup Folder
MalwareADVSTORESHELL

ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key.

T1560
Archive Collected Data
MalwareADVSTORESHELL

ADVSTORESHELL encrypts with the 3DES algorithm and a hardcoded key prior to exfiltration.

T1560.003
Archive via Custom Method
MalwareADVSTORESHELL

ADVSTORESHELL compresses output data generated by command execution with a custom implementation of the Lempel–Ziv–Welch (LZW) algorithm.

T1573.001
Symmetric Cryptography
MalwareCHOPSTICK

CHOPSTICK encrypts C2 communications with RC4.

T1573.002
Asymmetric Cryptography
MalwareCHOPSTICK

CHOPSTICK encrypts C2 communications with TLS.

T1573.002
Asymmetric Cryptography
MalwareXTunnel

XTunnel uses SSL/TLS and RC4 to encrypt traffic.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.