ATT&CKReferencesMandiant Cutting Edge Part 3 February 2024

Mandiant Cutting Edge Part 3 February 2024

Lin, M. et al. (2024, February 27). Cutting Edge, Part 3: Investigating Ivanti Connect Secure VPN Exploitation and Persistence Attempts. Retrieved March 1, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software3

Campaigns1

Procedure examples25

TechniqueUsed byProcedure example
T1055
Process Injection
CampaignCutting Edge

During Cutting Edge, threat actors used malicious SparkGateway plugins to inject shared objects into web process memory on compromised Ivanti Secure Connect VPNs to enable deployment of backdoors.

T1059.004
Unix Shell
MalwarePITSTOP

PITSTOP has the ability to receive shell commands over a Unix domain socket.

T1059.006
Python
CampaignCutting Edge

During Cutting Edge, threat actors used a Python reverse shell and the PySoxy SOCKS5 proxy tool.

T1070.004
File Deletion
CampaignCutting Edge

During Cutting Edge, threat actors deleted `/tmp/test1.txt` on compromised Ivanti Connect Secure VPNs which was used to hold stolen configuration and cache files.

T1070.006
Timestomp
CampaignCutting Edge

During Cutting Edge, threat actors changed timestamps of multiple files on compromised Ivanti Secure Connect VPNs to conceal malicious activity.

T1082
System Information Discovery
MalwareLITTLELAMB.WOOLTEA

LITTLELAMB.WOOLTEA can check the type of Ivanti VPN device it is running on by executing `first_run()` to identify the first four bytes of the motherboard serial number.

T1083
File and Directory Discovery
MalwareLITTLELAMB.WOOLTEA

LITTLELAMB.WOOLTEA can monitor for system upgrade events by checking for the presence of `/tmp/data/root/dev`.

T1090
Proxy
MalwareLITTLELAMB.WOOLTEA

LITTLELAMB.WOOLTEA has the ability to function as a SOCKS proxy.

T1095
Non-Application Layer Protocol
MalwareLITTLELAMB.WOOLTEA

LITTLELAMB.WOOLTEA can function as a stand-alone backdoor communicating over the `/tmp/clientsDownload.sock` socket.

T1095
Non-Application Layer Protocol
CampaignCutting Edge

During Cutting Edge, threat actors used the Unix socket and a reverse TCP shell for C2 communications.

T1105
Ingress Tool Transfer
MalwareBUSHWALK

BUSHWALK can write malicious payloads sent through a web request’s command parameter.

T1140
Deobfuscate/Decode Files or Information
MalwareBUSHWALK

BUSHWALK can Base64 decode and RC4 decrypt malicious payloads sent through a web request’s command parameter.

T1140
Deobfuscate/Decode Files or Information
MalwarePITSTOP

PITSTOP can deobfuscate base64 encoded and AES encrypted commands.

T1190
Exploit Public-Facing Application
CampaignCutting Edge

During Cutting Edge, threat actors exploited CVE-2023-46805 and CVE-2024-21887 in Ivanti Connect Secure VPN appliances to enable authentication bypass and command injection. A server-side request forgery (SSRF) vulnerability, CVE-2024-21893, was identified later and used to bypass mitigations for the initial two vulnerabilities by chaining with CVE-2024-21887.

T1205
Traffic Signaling
CampaignCutting Edge

During Cutting Edge, threat actors sent a magic 48-byte sequence to enable the PITSOCK backdoor to communicate via the `/tmp/clientsDownload.sock` socket.

T1205
Traffic Signaling
MalwareBUSHWALK

BUSHWALK can modify the `DSUserAgentCap.pm` Perl module on Ivanti Connect Secure VPNs and either activate or deactivate depending on the value of the user agent in incoming HTTP requests.

T1205.002
Socket Filters
MalwarePITSTOP

PITSTOP can listen and evaluate incoming commands on the domain socket, created by PITHOOK malware, located at `/data/runtime/cockpit/wd.fd` for a predefined magic byte sequence. PITSTOP can then duplicate the socket for further communication over TLS.

T1543
Create or Modify System Process
MalwareLITTLELAMB.WOOLTEA

LITTLELAMB.WOOLTEA can initialize itself as a daemon to run persistently in the background.

T1554
Compromise Host Software Binary
MalwareLITTLELAMB.WOOLTEA

LITTLELAMB.WOOLTEA can append malicious components to the `tmp/tmpmnt/bin/samba_upgrade.tar` archive inside the factory reset partition in attempt to persist post reset.

T1554
Compromise Host Software Binary
MalwareBUSHWALK

BUSHWALK can embed into the legitimate `querymanifest.cgi` file on compromised Ivanti Connect Secure VPNs.

T1559
Inter-Process Communication
MalwarePITSTOP

PITSTOP can listen over the Unix domain socket located at `/data/runtime/cockpit/wd.fd`.

T1573.002
Asymmetric Cryptography
MalwarePITSTOP

PITSTOP has the ability to communicate over TLS.

T1573.002
Asymmetric Cryptography
MalwareLITTLELAMB.WOOLTEA

LITTLELAMB.WOOLTEA can communicate over SSL using the private key from the Ivanti Connect Secure web server.

T1588.002
Tool
CampaignCutting Edge

During Cutting Edge, threat actors leveraged tools including Interactsh to identify vulnerable targets, PySoxy to simultaneously dispatch traffic between multiple endpoints, BusyBox to enable post exploitation activities, and Kubo Injector to inject shared objects into process memory.

T1595.002
Vulnerability Scanning
CampaignCutting Edge

During Cutting Edge, threat actors used the publicly available Interactsh tool to identify Ivanti Connect Secure VPNs vulnerable to CVE-2024-21893.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.