ATT&CKReferencesKaspersky Lyceum October 2021

Kaspersky Lyceum October 2021

Kayal, A. et al. (2021, October). LYCEUM REBORN: COUNTERINTELLIGENCE IN THE MIDDLE EAST. Retrieved June 14, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software2

Campaigns0

None recorded.

Procedure examples46

TechniqueUsed byProcedure example
T1001.001
Junk Data
MalwareKevin

Kevin can generate a sequence of dummy HTTP C2 requests to obscure traffic.

T1005
Data from Local System
MalwareKevin

Kevin can upload logs and other data from a compromised host.

T1008
Fallback Channels
MalwareKevin

Kevin can assign hard-coded fallback domains for C2.

T1016
System Network Configuration Discovery
MalwareKevin

Kevin can collect the MAC address and other information from a victim machine using `ipconfig/all`.

T1016
System Network Configuration Discovery
GroupHEXANE

HEXANE has used Ping and `tracert` for network discovery.

T1016.001
Internet Connection Discovery
GroupHEXANE

HEXANE has used tools including BITSAdmin to test internet connectivity from compromised hosts.

T1018
Remote System Discovery
GroupHEXANE

HEXANE has used `net view` to enumerate domain machines.

T1027.010
Command Obfuscation
GroupHEXANE

HEXANE has used Base64-encoded scripts.

T1027.013
Encrypted/Encoded File
MalwareMilan

Milan can encode files containing information about the targeted system.

T1027.013
Encrypted/Encoded File
MalwareKevin

Kevin has Base64-encoded its configuration file.

T1030
Data Transfer Size Limits
MalwareKevin

Kevin can exfiltrate data to the C2 server in 27-character chunks.

T1033
System Owner/User Discovery
GroupHEXANE

HEXANE has run `whoami` on compromised machines to identify the current user.

T1036.003
Rename Legitimate Utilities
MalwareKevin

Kevin has renamed an image of `cmd.exe` with a random name followed by a `.tmpl` extension.

T1041
Exfiltration Over C2 Channel
MalwareKevin

Kevin can send data from the victim host through a DNS C2 channel.

T1049
System Network Connections Discovery
GroupHEXANE

HEXANE has used netstat to monitor connections to specific ports.

T1053.005
Scheduled Task
GroupHEXANE

HEXANE has used a scheduled task to establish persistence for a keylogger.

T1056.001
Keylogging
GroupHEXANE

HEXANE has used a PowerShell-based keylogger named `kl.ps1`.

T1057
Process Discovery
GroupHEXANE

HEXANE has enumerated processes on targeted systems.

T1059.001
PowerShell
GroupHEXANE

HEXANE has used PowerShell-based tools and scripts for discovery and collection on compromised hosts.

T1059.003
Windows Command Shell
MalwareKevin

Kevin can use a renamed image of `cmd.exe` for execution.

T1059.005
Visual Basic
GroupHEXANE

HEXANE has used a VisualBasic script named `MicrosoftUpdator.vbs` for execution of a PowerShell keylogger.

T1069.001
Local Groups
GroupHEXANE

HEXANE has run `net localgroup` to enumerate local groups.

T1070.004
File Deletion
MalwareKevin

Kevin can delete files created on the victim's machine.

T1071.001
Web Protocols
MalwareKevin

Variants of Kevin can communicate with C2 over HTTP.

T1071.001
Web Protocols
MalwareMilan

Milan can use HTTPS for communication with C2.

T1071.004
DNS
MalwareKevin

Variants of Kevin can communicate over DNS through queries to the server for constructed domain names with embedded information.

T1071.004
DNS
MalwareMilan

Milan has the ability to use DNS for C2 communications.

T1074
Data Staged
MalwareKevin

Kevin can create directories to store logs and other collected data.

T1082
System Information Discovery
MalwareKevin

Kevin can enumerate the OS version and hostname of a targeted machine.

T1082
System Information Discovery
GroupHEXANE

HEXANE has collected the hostname of a compromised machine.

T1105
Ingress Tool Transfer
MalwareKevin

Kevin can download files to the compromised host.

T1105
Ingress Tool Transfer
GroupHEXANE

HEXANE has downloaded additional payloads and malicious scripts onto a compromised host.

T1106
Native API
MalwareMilan

Milan can use the API `DnsQuery_A` for DNS resolution.

T1106
Native API
MalwareKevin

Kevin can use the `ShowWindow` API to avoid detection.

T1132.001
Standard Encoding
MalwareKevin

Kevin can Base32 encode chunks of output files during exfiltration.

T1497
Virtualization/Sandbox Evasion
MalwareKevin

Kevin can sleep for a time interval between C2 communication attempts.

T1518
Software Discovery
GroupHEXANE

HEXANE has enumerated programs installed on an infected machine.

T1546.003
Windows Management Instrumentation Event Subscription
GroupHEXANE

HEXANE has used WMI event subscriptions for persistence.

T1546.003
Windows Management Instrumentation Event Subscription
MalwareKevin

Kevin can compile randomly-generated MOF files into the WMI repository to persistently run malware.

T1555
Credentials from Password Stores
GroupHEXANE

HEXANE has run `cmdkey` on victim machines to identify stored credentials.

T1555.003
Credentials from Web Browsers
GroupHEXANE

HEXANE has used a Mimikatz-based tool and a PowerShell script to steal passwords from Google Chrome.

T1564.003
Hidden Window
MalwareKevin

Kevin can hide the current window from the targeted user via the `ShowWindow` API function.

T1572
Protocol Tunneling
MalwareMilan

Milan can use a custom protocol tunneled through DNS or HTTP.

T1572
Protocol Tunneling
MalwareKevin

Kevin can use a custom protocol tunneled through DNS or HTTP.

T1585.002
Email Accounts
GroupHEXANE

HEXANE has established email accounts for use in domain registration including for ProtonMail addresses.

T1588.002
Tool
GroupHEXANE

HEXANE has acquired, and sometimes customized, open source tools such as Mimikatz, Empire, VNC remote access software, and DIG.net.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.