NSA, CISA, FBI, NCSC. (2021, July). Russian GRU Conducting Global Brute Force Campaign to Compromise Enterprise and Cloud Environments. Retrieved July 26, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupAPT28 | APT28 regularly deploys both publicly available (ex: Mimikatz) and custom password retrieval tools on victims. They have also dumped the LSASS process memory using the MiniDump function. |
| T1003.003 NTDS |
GroupAPT28 | APT28 has used the ntdsutil.exe utility to export the Active Directory database for credential access. |
| T1005 Data from Local System |
GroupAPT28 | APT28 has retrieved internal documents from machines inside victim environments, including by using Forfiles to stage documents before exfiltration. |
| T1021.002 SMB/Windows Admin Shares |
GroupAPT28 | APT28 has mapped network drives using Net and administrator credentials. |
| T1030 Data Transfer Size Limits |
GroupAPT28 | APT28 has split archived exfiltration files into chunks smaller than 1MB. |
| T1036 Masquerading |
GroupAPT28 | APT28 has renamed the WinRAR utility to avoid detection. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupAPT28 | APT28 has changed extensions on files containing exfiltrated data to make them appear benign, and renamed a web shell instance to appear as a legitimate OWA page. |
| T1039 Data from Network Shared Drive |
GroupAPT28 | APT28 has collected files from network shared drives. |
| T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol |
GroupAPT28 | APT28 has exfiltrated archives of collected data previously staged on a target's OWA server via HTTPS. |
| T1059.001 PowerShell |
GroupAPT28 | APT28 downloads and executes PowerShell scripts and performs PowerShell commands. |
| T1071.001 Web Protocols |
GroupAPT28 | Later implants used by APT28, such as CHOPSTICK, use a blend of HTTP, HTTPS, and other legitimate channels for C2, depending on module configuration. |
| T1071.003 Mail Protocols |
GroupAPT28 | APT28 has used IMAP, POP3, and SMTP for a communication channel in various implants, including using self-registered Google Mail accounts and later compromised email servers of its victims. |
| T1074.002 Remote Data Staging |
GroupAPT28 | APT28 has staged archives of collected data on a target's Outlook Web Access (OWA) server. |
| T1078 Valid Accounts |
GroupAPT28 | APT28 has used legitimate credentials to gain initial access, maintain access, and exfiltrate data from a victim network. The group has specifically used credentials stolen through a spearphishing email to login to the DCCC network. The group has also leveraged default manufacturer's passwords to gain initial access to corporate networks via IoT devices such as a VOIP phone, printer, and video decoder. |
| T1078.004 Cloud Accounts |
GroupAPT28 | APT28 has used compromised Office 365 service accounts with Global Administrator privileges to collect email from user inboxes. |
| T1098.002 Additional Email Delegate Permissions |
GroupAPT28 | APT28 has used a Powershell cmdlet to grant the |
| T1105 Ingress Tool Transfer |
GroupAPT28 | APT28 has downloaded additional files, including by using a first-stage downloader to contact the C2 server to obtain the second-stage implant. |
| T1110.001 Password Guessing |
GroupAPT28 | APT28 has used a brute-force/password-spray tooling that operated in two modes: in brute-force mode it typically sent over 300 authentication attempts per hour per targeted account over the course of several hours or days. APT28 has also used a Kubernetes cluster to conduct distributed, large-scale password guessing attacks. |
| T1110.003 Password Spraying |
GroupAPT28 | APT28 has used a brute-force/password-spray tooling that operated in two modes: in password-spraying mode it conducted approximately four authentication attempts per hour per targeted account over the course of several days or weeks. APT28 has also used a Kubernetes cluster to conduct distributed, large-scale password spray attacks. |
| T1114.002 Remote Email Collection |
GroupAPT28 | APT28 has collected emails from victim Microsoft Exchange servers. |
| T1133 External Remote Services |
GroupAPT28 | APT28 has used Tor and a variety of commercial VPN services to route brute force authentication attempts. |
| T1190 Exploit Public-Facing Application |
GroupAPT28 | APT28 has used a variety of public exploits, including CVE 2020-0688 and CVE 2020-17144, to gain execution on vulnerable Microsoft Exchange; they have also conducted SQL injection attacks against external websites. |
| T1213 Data from Information Repositories |
GroupAPT28 | APT28 has collected files from various information repositories. |
| T1218.011 Rundll32 |
GroupAPT28 | APT28 executed CHOPSTICK by using rundll32 commands such as |
| T1505.003 Web Shell |
GroupAPT28 | APT28 has used a modified and obfuscated version of the reGeorg web shell to maintain persistence on a target's Outlook Web Access (OWA) server. |
| T1560.001 Archive via Utility |
GroupAPT28 | APT28 has used a variety of utilities, including WinRAR, to archive collected data with password protection. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.