Volexity Threat Research. (2024, April 12). Zero-Day Exploitation of Unauthenticated Remote Code Execution Vulnerability in GlobalProtect (CVE-2024-3400). Retrieved November 20, 2024.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1001.001 Junk Data |
MalwareUPSTYLE | UPSTYLE retrieves a non-existent webpage from the command and control server then parses commands from the resulting error logs to decode commands to the web shell. |
| T1003.003 NTDS |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors obtained active directory credentials via the NTDS.DIT file. |
| T1005 Data from Local System |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors stole saved cookies and login data from targeted systems. |
| T1021.002 SMB/Windows Admin Shares |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors used SMB to pivot internally in victim networks. |
| T1021.006 Windows Remote Management |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors used WinRM to move laterally in targeted networks. |
| T1027.013 Encrypted/Encoded File |
MalwareUPSTYLE | UPSTYLE stores primary content as base64-encoded objects. |
| T1036 Masquerading |
MalwareUPSTYLE | UPSTYLE has masqueraded filenames using examples such as `update.py`. |
| T1053.003 Cron |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors configured cron jobs to retrieve payloads from actor-controlled infrastructure. |
| T1059.004 Unix Shell |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors piped output from stdout to bash for execution. |
| T1059.006 Python |
MalwareUPSTYLE | UPSTYLE is a Python-based application. |
| T1070.004 File Deletion |
MalwareUPSTYLE | UPSTYLE removes `bootstrap.min.css` after parsing command and control instructions, restoring the file to its original state. |
| T1070.006 Timestomp |
MalwareUPSTYLE | UPSTYLE restores timestamps to original values following modification. |
| T1071.001 Web Protocols |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors used `wget` via HTTP to retrieve payloads. |
| T1078 Valid Accounts |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors extracted sensitive credentials while moving laterally through compromised networks. |
| T1078.002 Domain Accounts |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors used a compromised domain admin account to move laterally. |
| T1090 Proxy |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors used the GO Simple Tunnel reverse proxy tool. |
| T1102.003 One-Way Communication |
MalwareUPSTYLE | UPSTYLE parses encoded commands from error logs after attempting to resolve a non-existing webpage from the command and control server. |
| T1105 Ingress Tool Transfer |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors downloaded additional payloads on compromised devices. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareUPSTYLE | UPSTYLE encodes its main content prior to loading via Python as base64-encoded blobs. |
| T1190 Exploit Public-Facing Application |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors exploited CVE-2024-3400 in Palo Alto Networks GlobalProtect. |
| T1546 Event Triggered Execution |
MalwareUPSTYLE | UPSTYLE creates a `.pth` file beginning with the text `import` so that any time another process or script attempts to reference the modified item the malicious code will also run. |
| T1559 Inter-Process Communication |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors wrote output to stdout then piped it to bash for execution. |
| T1584.003 Virtual Private Server |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors abused Virtual Private Servers to store malicious files. |
| T1584.006 Web Services |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors abused compromised AWS buckets to store files. |
| T1588.002 Tool |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors used the GO Simple Tunnel (GOST) reverse proxy tool. |
| T1665 Hide Infrastructure |
MalwareUPSTYLE | UPSTYLE attempts to retrieve a non-existent webpage from the command and control server resulting in hidden commands sent via resulting error messages. |
| T1685.006 Clear Linux or Mac System Logs |
MalwareUPSTYLE | UPSTYLE clears error logs after reading embedded commands for execution. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.