ATT&CKReferencesClearSky Siamesekitten August 2021

ClearSky Siamesekitten August 2021

ClearSky Cyber Security . (2021, August). New Iranian Espionage Campaign By “Siamesekitten” - Lyceum. Retrieved June 6, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software2

Campaigns0

None recorded.

Procedure examples44

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareMilan

Milan can upload files from a compromised host.

T1005
Data from Local System
MalwareShark

Shark can upload files to its C2.

T1008
Fallback Channels
MalwareShark

Shark can update its configuration to use a different C2 server.

T1016
System Network Configuration Discovery
MalwareMilan

Milan can run `C:\Windows\system32\cmd.exe /c cmd /c ipconfig /all 2>&1` to discover network settings.

T1021.005
VNC
MalwareDanBot

DanBot can use VNC for remote access to targeted systems.

T1027.013
Encrypted/Encoded File
MalwareShark

Shark can use encrypted and encoded files for C2 configuration.

T1027.013
Encrypted/Encoded File
MalwareMilan

Milan can encode files containing information about the targeted system.

T1029
Scheduled Transfer
MalwareShark

Shark can pause C2 communications for a specified time.

T1033
System Owner/User Discovery
MalwareMilan

Milan can identify users registered to a targeted machine.

T1036
Masquerading
MalwareMilan

Milan has used an executable named `companycatalogue` to appear benign.

T1036.005
Match Legitimate Resource Name or Location
MalwareShark

Shark binaries have been named `audioddg.pdb` and `Winlangdb.pdb` in order to appear legitimate.

T1036.005
Match Legitimate Resource Name or Location
MalwareDanBot

DanBot files have been named `UltraVNC.exe` and `WINVNC.exe` to appear as legitimate VNC tools.

T1036.007
Double File Extension
MalwareMilan

Milan has used an executable named `companycatalog.exe.config` to appear benign.

T1041
Exfiltration Over C2 Channel
MalwareShark

Shark has the ability to upload files from the compromised host over a DNS or HTTP C2 channel.

T1053.005
Scheduled Task
MalwareMilan

Milan can establish persistence on a targeted host with scheduled tasks.

T1059.003
Windows Command Shell
MalwareDanBot

DanBot has the ability to execute arbitrary commands via `cmd.exe`.

T1059.003
Windows Command Shell
MalwareShark

Shark has the ability to use `CMD` to execute commands.

T1059.003
Windows Command Shell
MalwareMilan

Milan can use `cmd.exe` for discovery actions on a targeted system.

T1070.004
File Deletion
MalwareMilan

Milan can delete files via `C:\Windows\system32\cmd.exe /c ping 1.1.1.1 -n 1 -w 3000 > Nul & rmdir /s /q`.

T1070.004
File Deletion
MalwareShark

Shark can delete files downloaded to the compromised host.

T1070.004
File Deletion
MalwareDanBot

DanBot can delete its configuration file after installation.

T1071.001
Web Protocols
MalwareShark

Shark has the ability to use HTTP in C2 communications.

T1071.001
Web Protocols
MalwareMilan

Milan can use HTTPS for communication with C2.

T1071.004
DNS
MalwareMilan

Milan has the ability to use DNS for C2 communications.

T1071.004
DNS
MalwareShark

Shark can use DNS in C2 communications.

T1074
Data Staged
MalwareShark

Shark has stored information in folders named `U1` and `U2` prior to exfiltration.

T1074.001
Local Data Staging
MalwareMilan

Milan has saved files prior to upload from a compromised host to folders beginning with the characters `a9850d2f`.

T1082
System Information Discovery
MalwareShark

Shark can collect the GUID of a targeted machine.

T1082
System Information Discovery
MalwareMilan

Milan can enumerate the targeted machine's name and GUID.

T1087.001
Local Account
MalwareMilan

Milan has run `C:\Windows\system32\cmd.exe /c cmd /c dir c:\users\ /s 2>&1` to discover local accounts.

T1105
Ingress Tool Transfer
MalwareShark

Shark can download additional files from its C2 via HTTP or DNS.

T1105
Ingress Tool Transfer
MalwareMilan

Milan has received files from C2 and stored them in log folders beginning with the character sequence `a9850d2f`.

T1140
Deobfuscate/Decode Files or Information
MalwareShark

Shark can extract and decrypt downloaded .zip files.

T1204.002
Malicious File
MalwareDanBot

DanBot has relied on victims' opening a malicious file for initial execution.

T1204.002
Malicious File
GroupHEXANE

HEXANE has relied on victim's executing malicious file attachments delivered via email or embedded within actor-controlled websites to deliver malware.

T1497.001
System Checks
MalwareShark

Shark can stop execution if the screen width of the targeted machine is not over 600 pixels.

T1559.001
Component Object Model
MalwareMilan

Milan can use a COM component to generate scheduled tasks.

T1568.002
Domain Generation Algorithms
MalwareShark

Shark can send DNS C2 communications using a unique domain generation algorithm.

T1583.001
Domains
GroupHEXANE

HEXANE has registered and operated domains for campaigns, often using a security or web technology theme or impersonating the targeted organization.

T1585.001
Social Media Accounts
GroupHEXANE

HEXANE has established fraudulent LinkedIn accounts impersonating HR department employees to target potential victims with fake job offers.

T1589
Gather Victim Identity Information
GroupHEXANE

HEXANE has identified specific potential victims at targeted organizations.

T1589.002
Email Addresses
GroupHEXANE

HEXANE has targeted executives, human resources staff, and IT personnel for spearphishing.

T1591.004
Identify Roles
GroupHEXANE

HEXANE has identified executives, HR, and IT staff at victim organizations for further targeting.

T1608.001
Upload Malware
GroupHEXANE

HEXANE has staged malware on fraudulent websites set up to impersonate targeted organizations.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.