ATT&CKReferencesUnit 42 Inception November 2018

Unit 42 Inception November 2018

Lancaster, T. (2018, November 5). Inception Attackers Target Europe with Year-old Office Vulnerability. Retrieved May 8, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples16

TechniqueUsed byProcedure example
T1059.001
PowerShell
MalwarePowerShower

PowerShower is a backdoor written in PowerShell.

T1059.001
PowerShell
GroupInception

Inception has used PowerShell to execute malicious commands and payloads.

T1059.005
Visual Basic
GroupInception

Inception has used VBScript to execute malicious commands and payloads.

T1059.005
Visual Basic
MalwarePowerShower

PowerShower has the ability to save and execute VBScript.

T1070.004
File Deletion
MalwarePowerShower

PowerShower has the ability to remove all files created during the dropper process.

T1071.001
Web Protocols
MalwarePowerShower

PowerShower has sent HTTP GET and POST requests to C2 servers to send information and receive instructions.

T1071.001
Web Protocols
GroupInception

Inception has used HTTP, HTTPS, and WebDav in network communications.

T1082
System Information Discovery
MalwarePowerShower

PowerShower has collected system information on the infected host.

T1112
Modify Registry
MalwarePowerShower

PowerShower has added a registry key so future powershell.exe instances are spawned off-screen by default, and has removed all registry entries that are left behind during the dropper process.

T1132.001
Standard Encoding
MalwarePowerShower

PowerShower has the ability to encode C2 communications with base64 encoding.

T1203
Exploitation for Client Execution
GroupInception

Inception has exploited CVE-2012-0158, CVE-2014-1761, CVE-2017-11882 and CVE-2018-0802 for execution.

T1204.002
Malicious File
GroupInception

Inception lured victims into clicking malicious files for machine reconnaissance and to execute malware.

T1221
Template Injection
GroupInception

Inception has used decoy documents to load malicious remote payloads via HTTP.

T1547.001
Registry Run Keys / Startup Folder
MalwarePowerShower

PowerShower sets up persistence with a Registry run key.

T1564.003
Hidden Window
MalwarePowerShower

PowerShower has added a registry key so future powershell.exe instances are spawned with coordinates for a window position off-screen by default.

T1566.001
Spearphishing Attachment
GroupInception

Inception has used weaponized documents attached to spearphishing emails for reconnaissance and initial compromise.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.