ATT&CKReferencesSymantec Sowbug Nov 2017

Symantec Sowbug Nov 2017

Symantec Security Response. (2017, November 7). Sowbug: Cyber espionage group targets South American and Southeast Asian governments. Retrieved November 16, 2017.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software2

Campaigns0

None recorded.

Procedure examples11

TechniqueUsed byProcedure example
T1003
OS Credential Dumping
GroupSowbug

Sowbug has used credential dumping tools.

T1036.005
Match Legitimate Resource Name or Location
MalwareStarloader

Starloader has masqueraded as legitimate software update packages such as Adobe Acrobat Reader and Intel.

T1036.005
Match Legitimate Resource Name or Location
GroupSowbug

Sowbug named its tools to masquerade as Windows or Adobe Reader software, such as by using the file name adobecms.exe and the directory CSIDL_APPDATA\microsoft\security.

T1039
Data from Network Shared Drive
GroupSowbug

Sowbug extracted Word documents from a file server on a victim network.

T1056.001
Keylogging
GroupSowbug

Sowbug has used keylogging tools.

T1059.003
Windows Command Shell
GroupSowbug

Sowbug has used command line during its intrusions.

T1082
System Information Discovery
GroupSowbug

Sowbug obtained OS version and hardware configuration from a victim.

T1083
File and Directory Discovery
GroupSowbug

Sowbug identified and extracted all Word documents on a server by using a command containing * .doc and *.docx. The actors also searched for documents based on a specific date range and attempted to identify all installed software on a victim.

T1135
Network Share Discovery
GroupSowbug

Sowbug listed remote shared drives that were accessible from a victim.

T1140
Deobfuscate/Decode Files or Information
MalwareStarloader

Starloader decrypts and executes shellcode from a file called Stars.jps.

T1560.001
Archive via Utility
GroupSowbug

Sowbug extracted documents and bundled them into a RAR archive.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.