ATT&CKReferencesQiAnXin APT-C-36 Feb2019

QiAnXin APT-C-36 Feb2019

QiAnXin Threat Intelligence Center. (2019, February 18). APT-C-36: Continuous Attacks Targeting Colombian Government Institutions and Corporations. Retrieved May 5, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples21

TechniqueUsed byProcedure example
T1021.001
Remote Desktop Protocol
ToolImminent Monitor

Imminent Monitor has a module for performing remote desktop access.

T1027
Obfuscated Files or Information
GroupAPT-C-36

APT-C-36 has used ConfuserEx to obfuscate its variant of Imminent Monitor, compressed payloads and RAT packages, and password protected encrypted email attachments to avoid detection. APT-C-36 has also compressed initial droppers into ZIP, LHA and UUE formats.

T1027
Obfuscated Files or Information
ToolImminent Monitor

Imminent Monitor has encrypted the spearphish attachments to avoid detection from email gateways; the debugger also encrypts information before sending to the C2.

T1036.004
Masquerade Task or Service
GroupAPT-C-36

APT-C-36 has disguised its scheduled tasks as those used by Google.

T1041
Exfiltration Over C2 Channel
ToolImminent Monitor

Imminent Monitor has uploaded a file containing debugger logs, network information and system information to the C2.

T1053.005
Scheduled Task
GroupAPT-C-36

APT-C-36 has used a macro function to set scheduled tasks, disguised as those used by Google.

T1059
Command and Scripting Interpreter
ToolImminent Monitor

Imminent Monitor has a CommandPromptPacket and ScriptPacket module(s) for creating a remote shell and executing scripts.

T1059.005
Visual Basic
GroupAPT-C-36

APT-C-36 has used VBScript for initial malware deployment including within a malicious Word document which is executed upon the document opening.

T1070.004
File Deletion
ToolImminent Monitor

Imminent Monitor has deleted files related to its dynamic debugger feature.

T1083
File and Directory Discovery
ToolImminent Monitor

Imminent Monitor has a dynamic debugging feature to check whether it is located in the %TEMP% directory, otherwise it copies itself there.

T1105
Ingress Tool Transfer
GroupAPT-C-36

APT-C-36 has downloaded binary data from a specified domain after the malicious document is opened.

T1106
Native API
ToolImminent Monitor

Imminent Monitor has leveraged CreateProcessW() call to execute the debugger.

T1123
Audio Capture
ToolImminent Monitor

Imminent Monitor has a remote microphone monitoring capability.

T1125
Video Capture
ToolImminent Monitor

Imminent Monitor has a remote webcam monitoring capability.

T1140
Deobfuscate/Decode Files or Information
ToolImminent Monitor

Imminent Monitor has decoded malware components that are then dropped to the system.

T1204.002
Malicious File
GroupAPT-C-36

APT-C-36 has prompted victims to open attachments and to accept macros in order to execute the subsequent payload. APT-C-36 has also lured victims into opening malicious files hosted on Google Drive that triggered WebDAV requests to download malware.

T1555.003
Credentials from Web Browsers
ToolImminent Monitor

Imminent Monitor has a PasswordRecoveryPacket module for recovering browser passwords.

T1564.001
Hidden Files and Directories
ToolImminent Monitor

Imminent Monitor has a dynamic debugging feature to set the file attribute to hidden.

T1566.001
Spearphishing Attachment
GroupAPT-C-36

APT-C-36 has used spearphishing emails with malicious .pdf and .docx files and password protected RAR attachments to avoid being detected by the email gateway.

T1571
Non-Standard Port
GroupAPT-C-36

APT-C-36 has used port 4050 for C2 communications.

T1588.002
Tool
GroupAPT-C-36

APT-C-36 utilizes tools well known in crime communities and has obtained and used a modified variant of Imminent Monitor.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.