Kayal, A. et al. (2021, October). LYCEUM REBORN: COUNTERINTELLIGENCE IN THE MIDDLE EAST. Retrieved June 14, 2022.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1001.001 Junk Data |
MalwareKevin | Kevin can generate a sequence of dummy HTTP C2 requests to obscure traffic. |
| T1005 Data from Local System |
MalwareKevin | Kevin can upload logs and other data from a compromised host. |
| T1008 Fallback Channels |
MalwareKevin | Kevin can assign hard-coded fallback domains for C2. |
| T1016 System Network Configuration Discovery |
MalwareKevin | Kevin can collect the MAC address and other information from a victim machine using `ipconfig/all`. |
| T1016 System Network Configuration Discovery |
GroupHEXANE | |
| T1016.001 Internet Connection Discovery |
GroupHEXANE | HEXANE has used tools including BITSAdmin to test internet connectivity from compromised hosts. |
| T1018 Remote System Discovery |
GroupHEXANE | HEXANE has used `net view` to enumerate domain machines. |
| T1027.010 Command Obfuscation |
GroupHEXANE | HEXANE has used Base64-encoded scripts. |
| T1027.013 Encrypted/Encoded File |
MalwareMilan | Milan can encode files containing information about the targeted system. |
| T1027.013 Encrypted/Encoded File |
MalwareKevin | Kevin has Base64-encoded its configuration file. |
| T1030 Data Transfer Size Limits |
MalwareKevin | Kevin can exfiltrate data to the C2 server in 27-character chunks. |
| T1033 System Owner/User Discovery |
GroupHEXANE | HEXANE has run `whoami` on compromised machines to identify the current user. |
| T1036.003 Rename Legitimate Utilities |
MalwareKevin | Kevin has renamed an image of `cmd.exe` with a random name followed by a `.tmpl` extension. |
| T1041 Exfiltration Over C2 Channel |
MalwareKevin | Kevin can send data from the victim host through a DNS C2 channel. |
| T1049 System Network Connections Discovery |
GroupHEXANE | HEXANE has used netstat to monitor connections to specific ports. |
| T1053.005 Scheduled Task |
GroupHEXANE | HEXANE has used a scheduled task to establish persistence for a keylogger. |
| T1056.001 Keylogging |
GroupHEXANE | HEXANE has used a PowerShell-based keylogger named `kl.ps1`. |
| T1057 Process Discovery |
GroupHEXANE | HEXANE has enumerated processes on targeted systems. |
| T1059.001 PowerShell |
GroupHEXANE | HEXANE has used PowerShell-based tools and scripts for discovery and collection on compromised hosts. |
| T1059.003 Windows Command Shell |
MalwareKevin | Kevin can use a renamed image of `cmd.exe` for execution. |
| T1059.005 Visual Basic |
GroupHEXANE | HEXANE has used a VisualBasic script named `MicrosoftUpdator.vbs` for execution of a PowerShell keylogger. |
| T1069.001 Local Groups |
GroupHEXANE | HEXANE has run `net localgroup` to enumerate local groups. |
| T1070.004 File Deletion |
MalwareKevin | Kevin can delete files created on the victim's machine. |
| T1071.001 Web Protocols |
MalwareKevin | Variants of Kevin can communicate with C2 over HTTP. |
| T1071.001 Web Protocols |
MalwareMilan | Milan can use HTTPS for communication with C2. |
| T1071.004 DNS |
MalwareKevin | Variants of Kevin can communicate over DNS through queries to the server for constructed domain names with embedded information. |
| T1071.004 DNS |
MalwareMilan | Milan has the ability to use DNS for C2 communications. |
| T1074 Data Staged |
MalwareKevin | Kevin can create directories to store logs and other collected data. |
| T1082 System Information Discovery |
MalwareKevin | Kevin can enumerate the OS version and hostname of a targeted machine. |
| T1082 System Information Discovery |
GroupHEXANE | HEXANE has collected the hostname of a compromised machine. |
| T1105 Ingress Tool Transfer |
MalwareKevin | Kevin can download files to the compromised host. |
| T1105 Ingress Tool Transfer |
GroupHEXANE | HEXANE has downloaded additional payloads and malicious scripts onto a compromised host. |
| T1106 Native API |
MalwareMilan | Milan can use the API `DnsQuery_A` for DNS resolution. |
| T1106 Native API |
MalwareKevin | Kevin can use the `ShowWindow` API to avoid detection. |
| T1132.001 Standard Encoding |
MalwareKevin | Kevin can Base32 encode chunks of output files during exfiltration. |
| T1497 Virtualization/Sandbox Evasion |
MalwareKevin | Kevin can sleep for a time interval between C2 communication attempts. |
| T1518 Software Discovery |
GroupHEXANE | HEXANE has enumerated programs installed on an infected machine. |
| T1546.003 Windows Management Instrumentation Event Subscription |
GroupHEXANE | HEXANE has used WMI event subscriptions for persistence. |
| T1546.003 Windows Management Instrumentation Event Subscription |
MalwareKevin | Kevin can compile randomly-generated MOF files into the WMI repository to persistently run malware. |
| T1555 Credentials from Password Stores |
GroupHEXANE | HEXANE has run `cmdkey` on victim machines to identify stored credentials. |
| T1555.003 Credentials from Web Browsers |
GroupHEXANE | HEXANE has used a Mimikatz-based tool and a PowerShell script to steal passwords from Google Chrome. |
| T1564.003 Hidden Window |
MalwareKevin | Kevin can hide the current window from the targeted user via the `ShowWindow` API function. |
| T1572 Protocol Tunneling |
MalwareMilan | Milan can use a custom protocol tunneled through DNS or HTTP. |
| T1572 Protocol Tunneling |
MalwareKevin | Kevin can use a custom protocol tunneled through DNS or HTTP. |
| T1585.002 Email Accounts |
GroupHEXANE | HEXANE has established email accounts for use in domain registration including for ProtonMail addresses. |
| T1588.002 Tool |
GroupHEXANE | HEXANE has acquired, and sometimes customized, open source tools such as Mimikatz, Empire, VNC remote access software, and DIG.net. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.