ATT&CKReferencesFireEye APT30

FireEye APT30

FireEye Labs. (2015, April). APT30 AND THE MECHANICS OF A LONG-RUNNING CYBER ESPIONAGE OPERATION. Retrieved November 17, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software5

Campaigns0

None recorded.

Procedure examples41

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareFLASHFLOOD

FLASHFLOOD searches for interesting files (either a default or customized set of file extensions) on the local system. FLASHFLOOD will scan the My Recent Documents, Desktop, Temporary Internet Files, and TEMP directories. FLASHFLOOD also collects information stored in the Windows Address Book.

T1008
Fallback Channels
MalwareNETEAGLE

NETEAGLE will attempt to detect if the infected host is configured to a proxy. If so, NETEAGLE will send beacons via an HTTP POST request; otherwise it will send beacons via UDP/6000.

T1012
Query Registry
MalwareBACKSPACE

BACKSPACE is capable of enumerating and making modifications to an infected system's Registry.

T1025
Data from Removable Media
MalwareFLASHFLOOD

FLASHFLOOD searches for interesting files (either a default or customized set of file extensions) on removable media and copies them to a staging area. The default file types copied would include data copied to the drive by SPACESHIP.

T1041
Exfiltration Over C2 Channel
MalwareNETEAGLE

NETEAGLE is capable of reading files over the C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareBACKSPACE

Adversaries can direct BACKSPACE to upload files to the C2 Server.

T1052.001
Exfiltration over USB
MalwareSPACESHIP

SPACESHIP copies staged data to removable drives when they are inserted into the system.

T1057
Process Discovery
MalwareNETEAGLE

NETEAGLE can send process listings over the C2 channel.

T1057
Process Discovery
MalwareBACKSPACE

BACKSPACE may collect information about running processes.

T1059.003
Windows Command Shell
MalwareNETEAGLE

NETEAGLE allows adversaries to execute shell commands on the infected host.

T1059.003
Windows Command Shell
MalwareBACKSPACE

Adversaries can direct BACKSPACE to execute from the command line on infected hosts, or have BACKSPACE create a reverse shell.

T1071.001
Web Protocols
MalwareNETEAGLE

NETEAGLE will attempt to detect if the infected host is configured to a proxy. If so, NETEAGLE will send beacons via an HTTP POST request. NETEAGLE will also use HTTP to download resources that contain an IP address and Port Number pair to connect to for further C2.

T1071.001
Web Protocols
MalwareBACKSPACE

BACKSPACE uses HTTP as a transport to communicate with its command server.

T1074.001
Local Data Staging
MalwareFLASHFLOOD

FLASHFLOOD stages data it copies from the local system or removable drives in the "%WINDIR%\$NtUninstallKB885884$\" directory.

T1074.001
Local Data Staging
MalwareSPACESHIP

SPACESHIP identifies files with certain extensions and copies them to a directory in the user's profile.

T1082
System Information Discovery
MalwareBACKSPACE

During its initial execution, BACKSPACE extracts operating system information from the infected host.

T1083
File and Directory Discovery
MalwareNETEAGLE

NETEAGLE allows adversaries to enumerate and modify the infected host's file system. It supports searching for directories, creating directories, listing directory contents, reading and writing to files, retrieving file attributes, and retrieving volume information.

T1083
File and Directory Discovery
MalwareFLASHFLOOD

FLASHFLOOD searches for interesting files (either a default or customized set of file extensions) on the local system and removable media.

T1083
File and Directory Discovery
MalwareSPACESHIP

SPACESHIP identifies files and directories for collection by searching for specific file extensions or file modification time.

T1083
File and Directory Discovery
MalwareBACKSPACE

BACKSPACE allows adversaries to search for files.

T1090.001
Internal Proxy
MalwareBACKSPACE

The "ZJ" variant of BACKSPACE allows "ZJ link" infections with Internet access to relay traffic from "ZJ listen" to a command server.

T1091
Replication Through Removable Media
MalwareSHIPSHAPE

APT30 may have used the SHIPSHAPE malware to move onto air-gapped networks. SHIPSHAPE targets removable drives to spread to other systems by modifying the drive to use Autorun to execute or by hiding legitimate document files and copying an executable to the folder with the same name as the legitimate document.

T1095
Non-Application Layer Protocol
MalwareNETEAGLE

If NETEAGLE does not detect a proxy configured on the infected machine, it will send beacons via UDP/6000. Also, after retrieving a C2 IP address and Port Number, NETEAGLE will initiate a TCP connection to this socket. The ensuing connection is a plaintext C2 channel in which commands are specified by DWORDs.

T1104
Multi-Stage Channels
MalwareBACKSPACE

BACKSPACE attempts to avoid detection by checking a first stage command and control server to determine if it should connect to the second stage server, which performs "louder" interactions with the malware.

T1112
Modify Registry
MalwareBACKSPACE

BACKSPACE is capable of deleting Registry keys, sub-keys, and values on a victim system.

T1132.002
Non-Standard Encoding
MalwareBACKSPACE

Newer variants of BACKSPACE will encode C2 communications with a custom system.

T1204.002
Malicious File
GroupAPT30

APT30 has relied on users to execute malicious file attachments delivered via spearphishing emails.

T1547.001
Registry Run Keys / Startup Folder
MalwareSHIPSHAPE

SHIPSHAPE achieves persistence by creating a shortcut in the Startup folder.

T1547.001
Registry Run Keys / Startup Folder
MalwareBACKSPACE

BACKSPACE achieves persistence by creating a shortcut to itself in the CSIDL_STARTUP directory.

T1547.001
Registry Run Keys / Startup Folder
MalwareFLASHFLOOD

FLASHFLOOD achieves persistence by making an entry in the Registry's Run key.

T1547.001
Registry Run Keys / Startup Folder
MalwareNETEAGLE

The "SCOUT" variant of NETEAGLE achieves persistence by adding itself to the HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key.

T1547.001
Registry Run Keys / Startup Folder
MalwareSPACESHIP

SPACESHIP achieves persistence by creating a shortcut in the current user's Startup folder.

T1547.009
Shortcut Modification
MalwareSHIPSHAPE

SHIPSHAPE achieves persistence by creating a shortcut in the Startup folder.

T1547.009
Shortcut Modification
MalwareSPACESHIP

SPACESHIP achieves persistence by creating a shortcut in the current user's Startup folder.

T1547.009
Shortcut Modification
MalwareBACKSPACE

BACKSPACE achieves persistence by creating a shortcut to itself in the CSIDL_STARTUP directory.

T1560.003
Archive via Custom Method
MalwareFLASHFLOOD

FLASHFLOOD employs the same encoding scheme as SPACESHIP for data it stages. Data is compressed with zlib, and bytes are rotated four times before being XOR'ed with 0x23.

T1560.003
Archive via Custom Method
MalwareSPACESHIP

Data SPACESHIP copies to the staging area is compressed with zlib. Bytes are rotated by four positions and XOR'ed with 0x23.

T1566.001
Spearphishing Attachment
GroupAPT30

APT30 has used spearphishing emails with malicious DOC attachments.

T1568
Dynamic Resolution
MalwareNETEAGLE

NETEAGLE can use HTTP to download resources that contain an IP address and port number pair to connect to for C2.

T1573.001
Symmetric Cryptography
MalwareNETEAGLE

NETEAGLE will decrypt resources it downloads with HTTP requests by using RC4 with the key "ScoutEagle."

T1686
Disable or Modify System Firewall
MalwareBACKSPACE

The "ZR" variant of BACKSPACE will check to see if known host-based firewalls are installed on the infected systems. BACKSPACE will attempt to establish a C2 channel, then will examine open windows to identify a pop-up from the firewall software and will simulate a mouse-click to allow the connection to proceed.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.