ATT&CKReferencesTrend Micro Iron Tiger April 2021

Trend Micro Iron Tiger April 2021

Lunghi, D. and Lu, K. (2021, April 9). Iron Tiger APT Updates Toolkit With Evolved SysUpdate Malware. Retrieved November 12, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software3

Campaigns0

None recorded.

Procedure examples38

TechniqueUsed byProcedure example
T1027.002
Software Packing
MalwareSysUpdate

SysUpdate has been packed with VMProtect.

T1027.002
Software Packing
GroupThreat Group-3390

Threat Group-3390 has packed malware and tools, including using VMProtect.

T1027.002
Software Packing
MalwareHyperBro

HyperBro has the ability to pack its payload.

T1027.011
Fileless Storage
MalwareSysUpdate

SysUpdate can store its encoded configuration file within Software\Classes\scConfig in either HKEY_LOCAL_MACHINE or HKEY_CURRENT_USER.

T1027.013
Encrypted/Encoded File
MalwareSysUpdate

SysUpdate can encrypt and encode its configuration file.

T1027.015
Compression
MalwarePandora

Pandora has the ability to compress stings with QuickLZ.

T1047
Windows Management Instrumentation
MalwareSysUpdate

SysUpdate can use WMI for execution on a compromised host.

T1055
Process Injection
MalwarePandora

Pandora can start and inject code into a new `svchost` process.

T1057
Process Discovery
MalwarePandora

Pandora can monitor processes on a compromised host.

T1068
Exploitation for Privilege Escalation
MalwarePandora

Pandora can use CVE-2017-15303 to bypass Windows Driver Signature Enforcement (DSE) protection and load its driver.

T1070.004
File Deletion
MalwareSysUpdate

SysUpdate can delete its configuration file from the targeted system.

T1071.001
Web Protocols
MalwarePandora

Pandora can communicate over HTTP.

T1082
System Information Discovery
MalwareSysUpdate

SysUpdate can collect a system's architecture, operating system version, and hostname.

T1083
File and Directory Discovery
MalwareSysUpdate

SysUpdate can search files on a compromised host.

T1105
Ingress Tool Transfer
MalwarePandora

Pandora can load additional drivers and files onto a victim machine.

T1105
Ingress Tool Transfer
MalwareSysUpdate

SysUpdate has the ability to download files to a compromised host.

T1112
Modify Registry
MalwarePandora

Pandora can write an encrypted token to the Registry to enable processing of remote commands.

T1112
Modify Registry
GroupThreat Group-3390

A Threat Group-3390 tool has created new Registry keys under `HKEY_CURRENT_USER\Software\Classes\` and `HKLM\SYSTEM\CurrentControlSet\services`.

T1112
Modify Registry
MalwareSysUpdate

SysUpdate can write its configuration file to Software\Classes\scConfig in either HKEY_LOCAL_MACHINE or HKEY_CURRENT_USER.

T1113
Screen Capture
MalwareSysUpdate

SysUpdate has the ability to capture screenshots.

T1140
Deobfuscate/Decode Files or Information
MalwareSysUpdate

SysUpdate can deobfuscate packed binaries in memory.

T1140
Deobfuscate/Decode Files or Information
MalwareHyperBro

HyperBro can unpack and decrypt its payload prior to execution.

T1190
Exploit Public-Facing Application
GroupThreat Group-3390

Threat Group-3390 has exploited the Microsoft SharePoint vulnerability CVE-2019-0604 and CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065 in Exchange Server.

T1195.002
Compromise Software Supply Chain
GroupThreat Group-3390

Threat Group-3390 has compromised the Able Desktop installer to gain access to victim's environments.

T1203
Exploitation for Client Execution
GroupThreat Group-3390

Threat Group-3390 has exploited CVE-2018-0798 in Equation Editor.

T1205
Traffic Signaling
MalwarePandora

Pandora can identify if incoming HTTP traffic contains a token and if so it will intercept the traffic and process the received command.

T1543.003
Windows Service
MalwareSysUpdate

SysUpdate can create a service to establish persistence.

T1543.003
Windows Service
MalwarePandora

Pandora has the ability to gain system privileges through Windows services.

T1547.001
Registry Run Keys / Startup Folder
MalwareSysUpdate

SysUpdate can use a Registry Run key to establish persistence.

T1553.006
Code Signing Policy Modification
MalwarePandora

Pandora can use CVE-2017-15303 to disable Windows Driver Signature Enforcement (DSE) protection and load its driver.

T1564.001
Hidden Files and Directories
MalwareSysUpdate

SysUpdate has the ability to set file attributes to hidden.

T1569.002
Service Execution
MalwareSysUpdate

SysUpdate can manage services and processes.

T1569.002
Service Execution
MalwarePandora

Pandora has the ability to install itself as a Windows service.

T1573.001
Symmetric Cryptography
MalwarePandora

Pandora has the ability to encrypt communications with D3DES.

T1574.001
DLL
MalwarePandora

Pandora can use DLL side-loading to execute malicious payloads.

T1574.001
DLL
MalwareHyperBro

HyperBro has used a legitimate application to sideload a DLL to decrypt, decompress, and run a payload.

T1574.001
DLL
MalwareSysUpdate

SysUpdate can load DLLs through vulnerable legitimate executables.

T1680
Local Storage Discovery
MalwareSysUpdate

SysUpdate can collect a system's drive information.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.