ATT&CKReferencesESET EvasivePanda 2024

ESET EvasivePanda 2024

Ahn Ho, Facundo Muñoz, & Marc-Etienne M.Léveillé. (2024, March 7). Evasive Panda leverages Monlam Festival to target Tibetans. Retrieved July 25, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples19

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareNightdoor

Nightdoor gathers information on victim system network configuration such as MAC addresses.

T1033
System Owner/User Discovery
MalwareNightdoor

Nightdoor gathers information on victim system users and usernames.

T1053.005
Scheduled Task
GroupDaggerfly

Daggerfly has attempted to use scheduled tasks for persistence in victim environments.

T1057
Process Discovery
MalwareNightdoor

Nightdoor can collect information on installed applications via Windows registry keys, as well as collecting information on running processes.

T1070.004
File Deletion
MalwareNightdoor

Nightdoor can self-delete.

T1071
Application Layer Protocol
MalwareNightdoor

Nightdoor uses TCP and UDP communication for command and control traffic.

T1071.001
Web Protocols
GroupDaggerfly

Daggerfly uses HTTP for command and control communication.

T1082
System Information Discovery
MalwareNightdoor

Nightdoor gathers information on the victim system such as CPU and Computer name as well as device drivers.

T1082
System Information Discovery
GroupDaggerfly

Daggerfly utilizes victim machine operating system information to create custom User Agent strings for subsequent command and control communication.

T1102
Web Service
MalwareNightdoor

Nightdoor can utilize Microsoft OneDrive or Google Drive for command and control purposes.

T1124
System Time Discovery
MalwareNightdoor

Nightdoor can identify the system local time information.

T1189
Drive-by Compromise
GroupDaggerfly

Daggerfly has used strategic website compromise for initial access against victims.

T1195.002
Compromise Software Supply Chain
GroupDaggerfly

Daggerfly is associated with several supply chain compromises using malicious updates to compromise victims.

T1204.001
Malicious Link
GroupDaggerfly

Daggerfly has used strategic website compromise to deliver a malicious link requiring user interaction.

T1553.002
Code Signing
GroupDaggerfly

Daggerfly has used signed, but not notarized, malicious files for execution in macOS environments.

T1574.001
DLL
GroupDaggerfly

Daggerfly has used legitimate software to side-load PlugX loaders onto victim systems. Daggerfly is also linked to multiple other instances of side-loading for initial loading activity.

T1584.004
Server
GroupDaggerfly

Daggerfly compromised web servers hosting updates for software as part of a supply chain intrusion.

T1587.002
Code Signing Certificates
GroupDaggerfly

Daggerfly created code signing certificates to sign malicious macOS files.

T1680
Local Storage Discovery
MalwareNightdoor

Nightdoor can collect information about disk drives, their total and free space, and file system type.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.