ATT&CKReferencesMandiant Fortinet Zero Day

Mandiant Fortinet Zero Day

Marvi, A. et al.. (2023, March 16). Fortinet Zero-Day and Custom Malware Used by Suspected Chinese Actor in Espionage Operation. Retrieved March 22, 2023.

Open the source

Techniques2

Groups1

Software2

Campaigns0

None recorded.

Procedure examples33

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareCASTLETAP

CASTLETAP can execute a C2 command to transfer files from victim machines.

T1021.004
SSH
GroupUNC3886

UNC3886 has established remote SSH access to targeted ESXi hosts.

T1036.004
Masquerade Task or Service
GroupUNC3886

UNC3886 has named a file ‘fgfm’ in an attempt to disguise it as the legitimate service ‘fgfmd’ which facilitates communication between FortiManager and the FortiGate firewall.

T1037
Boot or Logon Initialization Scripts
GroupUNC3886

UNC3886 has attempted to bypass digital signature verification checks at startup by adding a command to the startup config `/etc/init.d/localnet` within the rootfs.gz archive of both FortiManager and FortiAnalyzer devices.

T1040
Network Sniffing
MalwareCASTLETAP

CASTLETAP has the ability to create a raw promiscuous socket to sniff network traffic.

T1059.004
Unix Shell
MalwareCASTLETAP

CASTLETAP has the ability to spawn BusyBox command shell in victim environments.

T1059.006
Python
MalwareTHINCRUST

THINCRUST can use Python scripts for command execution.

T1070.004
File Deletion
GroupUNC3886

UNC3886 has used the the esxcli command line to remove files created by malicious vSphere Installation Bundles from disk.

T1070.007
Clear Network Connection History and Configurations
GroupUNC3886

UNC3886 has cleared specific events that contained the threat actor’s IP address from multiple log sources.

T1071.001
Web Protocols
MalwareTHINCRUST

THINCRUST can use HTTP POST requests in C2 communications.

T1095
Non-Application Layer Protocol
GroupUNC3886

UNC3886 has deployed backdoors that communicate over TCP to compromised network devices and over VMCI to ESXi hosts.

T1095
Non-Application Layer Protocol
MalwareREPTILE

REPTILE can communicate using TLS over raw TCP.

T1105
Ingress Tool Transfer
MalwareCASTLETAP

CASTLETAP can transfer files to compromised network devices.

T1140
Deobfuscate/Decode Files or Information
MalwareCASTLETAP

CASTLETAP can filter and deobfuscate an XOR encrypted activation string in the payload of an ICMP echo request.

T1140
Deobfuscate/Decode Files or Information
MalwareTHINCRUST

THINCRUST can deobfuscate RSA encrypted C2 commands received through the DEVICEID cookie.

T1190
Exploit Public-Facing Application
GroupUNC3886

UNC3886 has exploited CVE-2022-42475 in FortiOS SSL VPNs to obtain access.

T1205
Traffic Signaling
MalwareREPTILE

The REPTILE reverse shell component can listen for a specialized packet in TCP, UDP, or ICMP for activation.

T1205
Traffic Signaling
GroupUNC3886

UNC3886 has used the TABLEFLIP traffic redirection utility to listen for specialized command packets on compromised FortiManager devices.

T1205.001
Port Knocking
GroupUNC3886

UNC3886 maintained persistence on FortiGate Firewalls through ICMP port knocking.

T1205.002
Socket Filters
MalwareCASTLETAP

CASTLETAP can listen for a specialized ICMP packet for activation on compromised network devices.

T1505.006
vSphere Installation Bundles
GroupUNC3886

UNC3886 has used vSphere Installation Bundles (VIBs) to install malware and establish persistence across ESXi hypervisors.

T1554
Compromise Host Software Binary
GroupUNC3886

UNC3886 has trojanized Fortinet firmware and replaced the legitimate `/usr/bin/tac_plus` TACACS+ daemon for Linux with a malicious version containing credential logging functionality.

T1564.011
Ignore Process Interrupts
GroupUNC3886

UNC3886 modified the startup file `/etc/init.d/localnet` to execute the line `nohup /bin/support &` so the script would run when the system was rebooted.

T1573.001
Symmetric Cryptography
MalwareTHINCRUST

THINCRUST can process RSA encryted C2 commands.

T1573.001
Symmetric Cryptography
MalwareCASTLETAP

CASTLETAP can receive a 9-byte XOR encrypted activation string in the payload of an ICMP echo request packet.

T1573.002
Asymmetric Cryptography
MalwareCASTLETAP

CASTLETAP can initiate a C2 connection over an SSL socket.

T1573.002
Asymmetric Cryptography
MalwareREPTILE

REPTILE can use TLS over raw TCP for secure C2.

T1587.001
Malware
GroupUNC3886

UNC3886 has deployed custom malware families on Fortinet and VMware systems.

T1587.004
Exploits
GroupUNC3886

UNC3886 has used zero-day vulnerabilities CVE-2022-41328 against FortiOS and CVE-2023-20867 and CVE-2023-34048 against VMware vCenter.

T1675
ESXi Administration Command
GroupUNC3886

UNC3886 used `vmtoolsd.exe` to run commands on guest virtual machines from a compromised ESXi host.

T1685
Disable or Modify Tools
GroupUNC3886

UNC3886 has disabled OpenSSL digital signature verification of system files through corruption of boot files.

T1686
Disable or Modify System Firewall
MalwareTHINCRUST

THINCRUST can use the Django python module "django.views.decorators.csrf” along with the decorator “csrf_exempt” within victim firewalls to disable cross-site request forgery protections.

T1686
Disable or Modify System Firewall
GroupUNC3886

UNC3886 has used the TABLEFLIP traffic redirection utility and the esxcli command line to modify firewall rules.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.