ATT&CKReferencesSymantec Daggerfly 2023

Symantec Daggerfly 2023

Threat Hunter Team. (2023, April 20). Daggerfly: APT Actor Targets Telecoms Company in Africa. Retrieved July 25, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples21

TechniqueUsed byProcedure example
T1003
OS Credential Dumping
MalwareMgBot

MgBot includes modules for dumping and capturing credentials from process memory.

T1003.002
Security Account Manager
GroupDaggerfly

Daggerfly used Reg to dump the Security Account Manager (SAM) hive from victim machines for follow-on credential extraction.

T1012
Query Registry
GroupDaggerfly

Daggerfly used Reg to dump the Security Account Manager (SAM), System, and Security Windows registry hives from victim machines.

T1018
Remote System Discovery
MalwareMgBot

MgBot includes modules for performing ARP scans of local connected systems.

T1033
System Owner/User Discovery
MalwareMgBot

MgBot includes modules for identifying local users and administrators on victim machines.

T1036.003
Rename Legitimate Utilities
GroupDaggerfly

Daggerfly used a renamed version of rundll32.exe, such as "dbengin.exe" located in the `ProgramData\Microsoft\PlayReady` directory, to proxy malicious DLL execution.

T1046
Network Service Discovery
MalwareMgBot

MgBot includes modules for performing HTTP and server service scans.

T1056.001
Keylogging
MalwareMgBot

MgBot includes keylogger payloads focused on the QQ chat application.

T1057
Process Discovery
MalwareMgBot

MgBot includes a module for establishing a process watchdog for itself, identifying if the MgBot process is still running.

T1059.001
PowerShell
GroupDaggerfly

Daggerfly used PowerShell to download and execute remote-hosted files on victim systems.

T1087.001
Local Account
MalwareMgBot

MgBot includes modules for identifying local administrator accounts on victim systems.

T1087.002
Domain Account
MalwareMgBot

MgBot includes modules for collecting information on Active Directory domain accounts.

T1105
Ingress Tool Transfer
GroupDaggerfly

Daggerfly has used PowerShell and BITSAdmin to retrieve follow-on payloads from external locations for execution on victim machines.

T1115
Clipboard Data
MalwareMgBot

MgBot can capture clipboard data.

T1123
Audio Capture
MalwareMgBot

MgBot can capture input and output audio streams from infected devices.

T1136.001
Local Account
GroupDaggerfly

Daggerfly created a local account on victim machines to maintain access.

T1218.011
Rundll32
GroupDaggerfly

Daggerfly proxied execution of malicious DLLs through a renamed rundll32.exe binary.

T1482
Domain Trust Discovery
MalwareMgBot

MgBot includes modules for collecting information on local domain users and permissions.

T1555
Credentials from Password Stores
MalwareMgBot

MgBot includes modules for stealing stored credentials from Outlook and Foxmail email client software.

T1555.003
Credentials from Web Browsers
MalwareMgBot

MgBot includes modules for stealing credentials from various browsers and applications, including Chrome, Opera, Firefox, Foxmail, QQBrowser, FileZilla, and WinSCP.

T1574.001
DLL
GroupDaggerfly

Daggerfly has used legitimate software to side-load PlugX loaders onto victim systems. Daggerfly is also linked to multiple other instances of side-loading for initial loading activity.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.