QiAnXin Threat Intelligence Center. (2019, February 18). APT-C-36: Continuous Attacks Targeting Colombian Government Institutions and Corporations. Retrieved May 5, 2020.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1021.001 Remote Desktop Protocol |
ToolImminent Monitor | Imminent Monitor has a module for performing remote desktop access. |
| T1027 Obfuscated Files or Information |
GroupAPT-C-36 | APT-C-36 has used ConfuserEx to obfuscate its variant of Imminent Monitor, compressed payloads and RAT packages, and password protected encrypted email attachments to avoid detection. APT-C-36 has also compressed initial droppers into ZIP, LHA and UUE formats. |
| T1027 Obfuscated Files or Information |
ToolImminent Monitor | Imminent Monitor has encrypted the spearphish attachments to avoid detection from email gateways; the debugger also encrypts information before sending to the C2. |
| T1036.004 Masquerade Task or Service |
GroupAPT-C-36 | APT-C-36 has disguised its scheduled tasks as those used by Google. |
| T1041 Exfiltration Over C2 Channel |
ToolImminent Monitor | Imminent Monitor has uploaded a file containing debugger logs, network information and system information to the C2. |
| T1053.005 Scheduled Task |
GroupAPT-C-36 | APT-C-36 has used a macro function to set scheduled tasks, disguised as those used by Google. |
| T1059 Command and Scripting Interpreter |
ToolImminent Monitor | Imminent Monitor has a CommandPromptPacket and ScriptPacket module(s) for creating a remote shell and executing scripts. |
| T1059.005 Visual Basic |
GroupAPT-C-36 | APT-C-36 has used VBScript for initial malware deployment including within a malicious Word document which is executed upon the document opening. |
| T1070.004 File Deletion |
ToolImminent Monitor | Imminent Monitor has deleted files related to its dynamic debugger feature. |
| T1083 File and Directory Discovery |
ToolImminent Monitor | Imminent Monitor has a dynamic debugging feature to check whether it is located in the %TEMP% directory, otherwise it copies itself there. |
| T1105 Ingress Tool Transfer |
GroupAPT-C-36 | APT-C-36 has downloaded binary data from a specified domain after the malicious document is opened. |
| T1106 Native API |
ToolImminent Monitor | Imminent Monitor has leveraged CreateProcessW() call to execute the debugger. |
| T1123 Audio Capture |
ToolImminent Monitor | Imminent Monitor has a remote microphone monitoring capability. |
| T1125 Video Capture |
ToolImminent Monitor | Imminent Monitor has a remote webcam monitoring capability. |
| T1140 Deobfuscate/Decode Files or Information |
ToolImminent Monitor | Imminent Monitor has decoded malware components that are then dropped to the system. |
| T1204.002 Malicious File |
GroupAPT-C-36 | APT-C-36 has prompted victims to open attachments and to accept macros in order to execute the subsequent payload. APT-C-36 has also lured victims into opening malicious files hosted on Google Drive that triggered WebDAV requests to download malware. |
| T1555.003 Credentials from Web Browsers |
ToolImminent Monitor | Imminent Monitor has a PasswordRecoveryPacket module for recovering browser passwords. |
| T1564.001 Hidden Files and Directories |
ToolImminent Monitor | Imminent Monitor has a dynamic debugging feature to set the file attribute to hidden. |
| T1566.001 Spearphishing Attachment |
GroupAPT-C-36 | APT-C-36 has used spearphishing emails with malicious .pdf and .docx files and password protected RAR attachments to avoid being detected by the email gateway. |
| T1571 Non-Standard Port |
GroupAPT-C-36 | APT-C-36 has used port 4050 for C2 communications. |
| T1588.002 Tool |
GroupAPT-C-36 | APT-C-36 utilizes tools well known in crime communities and has obtained and used a modified variant of Imminent Monitor. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.