Lunghi, D. and Lu, K. (2021, April 9). Iron Tiger APT Updates Toolkit With Evolved SysUpdate Malware. Retrieved November 12, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.002 Software Packing |
MalwareSysUpdate | SysUpdate has been packed with VMProtect. |
| T1027.002 Software Packing |
GroupThreat Group-3390 | Threat Group-3390 has packed malware and tools, including using VMProtect. |
| T1027.002 Software Packing |
MalwareHyperBro | HyperBro has the ability to pack its payload. |
| T1027.011 Fileless Storage |
MalwareSysUpdate | SysUpdate can store its encoded configuration file within |
| T1027.013 Encrypted/Encoded File |
MalwareSysUpdate | SysUpdate can encrypt and encode its configuration file. |
| T1027.015 Compression |
MalwarePandora | Pandora has the ability to compress stings with QuickLZ. |
| T1047 Windows Management Instrumentation |
MalwareSysUpdate | SysUpdate can use WMI for execution on a compromised host. |
| T1055 Process Injection |
MalwarePandora | Pandora can start and inject code into a new `svchost` process. |
| T1057 Process Discovery |
MalwarePandora | Pandora can monitor processes on a compromised host. |
| T1068 Exploitation for Privilege Escalation |
MalwarePandora | Pandora can use CVE-2017-15303 to bypass Windows Driver Signature Enforcement (DSE) protection and load its driver. |
| T1070.004 File Deletion |
MalwareSysUpdate | SysUpdate can delete its configuration file from the targeted system. |
| T1071.001 Web Protocols |
MalwarePandora | Pandora can communicate over HTTP. |
| T1082 System Information Discovery |
MalwareSysUpdate | SysUpdate can collect a system's architecture, operating system version, and hostname. |
| T1083 File and Directory Discovery |
MalwareSysUpdate | SysUpdate can search files on a compromised host. |
| T1105 Ingress Tool Transfer |
MalwarePandora | Pandora can load additional drivers and files onto a victim machine. |
| T1105 Ingress Tool Transfer |
MalwareSysUpdate | SysUpdate has the ability to download files to a compromised host. |
| T1112 Modify Registry |
MalwarePandora | Pandora can write an encrypted token to the Registry to enable processing of remote commands. |
| T1112 Modify Registry |
GroupThreat Group-3390 | A Threat Group-3390 tool has created new Registry keys under `HKEY_CURRENT_USER\Software\Classes\` and `HKLM\SYSTEM\CurrentControlSet\services`. |
| T1112 Modify Registry |
MalwareSysUpdate | SysUpdate can write its configuration file to |
| T1113 Screen Capture |
MalwareSysUpdate | SysUpdate has the ability to capture screenshots. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareSysUpdate | SysUpdate can deobfuscate packed binaries in memory. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareHyperBro | HyperBro can unpack and decrypt its payload prior to execution. |
| T1190 Exploit Public-Facing Application |
GroupThreat Group-3390 | Threat Group-3390 has exploited the Microsoft SharePoint vulnerability CVE-2019-0604 and CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065 in Exchange Server. |
| T1195.002 Compromise Software Supply Chain |
GroupThreat Group-3390 | Threat Group-3390 has compromised the Able Desktop installer to gain access to victim's environments. |
| T1203 Exploitation for Client Execution |
GroupThreat Group-3390 | Threat Group-3390 has exploited CVE-2018-0798 in Equation Editor. |
| T1205 Traffic Signaling |
MalwarePandora | Pandora can identify if incoming HTTP traffic contains a token and if so it will intercept the traffic and process the received command. |
| T1543.003 Windows Service |
MalwareSysUpdate | SysUpdate can create a service to establish persistence. |
| T1543.003 Windows Service |
MalwarePandora | Pandora has the ability to gain system privileges through Windows services. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareSysUpdate | SysUpdate can use a Registry Run key to establish persistence. |
| T1553.006 Code Signing Policy Modification |
MalwarePandora | Pandora can use CVE-2017-15303 to disable Windows Driver Signature Enforcement (DSE) protection and load its driver. |
| T1564.001 Hidden Files and Directories |
MalwareSysUpdate | SysUpdate has the ability to set file attributes to hidden. |
| T1569.002 Service Execution |
MalwareSysUpdate | SysUpdate can manage services and processes. |
| T1569.002 Service Execution |
MalwarePandora | Pandora has the ability to install itself as a Windows service. |
| T1573.001 Symmetric Cryptography |
MalwarePandora | Pandora has the ability to encrypt communications with D3DES. |
| T1574.001 DLL |
MalwarePandora | Pandora can use DLL side-loading to execute malicious payloads. |
| T1574.001 DLL |
MalwareHyperBro | HyperBro has used a legitimate application to sideload a DLL to decrypt, decompress, and run a payload. |
| T1574.001 DLL |
MalwareSysUpdate | SysUpdate can load DLLs through vulnerable legitimate executables. |
| T1680 Local Storage Discovery |
MalwareSysUpdate | SysUpdate can collect a system's drive information. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.