ATT&CKReferencesGoogle Cloud APT41 2024

Google Cloud APT41 2024

Mike Stokkel et al. (2024, July 18). APT41 Has Arisen From the DUST. Retrieved September 16, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software2

Campaigns1

Procedure examples58

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareDUSTTRAP

DUSTTRAP can gather data from infected systems.

T1010
Application Window Discovery
MalwareDUSTTRAP

DUSTTRAP can enumerate running application windows.

T1012
Query Registry
MalwareDUSTTRAP

DUSTTRAP can enumerate Registry items.

T1016
System Network Configuration Discovery
MalwareDUSTTRAP

DUSTTRAP can enumerate infected system network information.

T1018
Remote System Discovery
MalwareDUSTTRAP

DUSTTRAP can use `ping` to identify remote hosts within the victim network.

T1027.009
Embedded Payloads
MalwareDUSTTRAP

DUSTTRAP contains additional embedded DLLs and configuration files that are loaded into memory during execution.

T1027.009
Embedded Payloads
MalwareDUSTPAN

DUSTPAN decrypts and executes an embedded payload.

T1027.013
Encrypted/Encoded File
CampaignAPT41 DUST

APT41 DUST used encrypted payloads decrypted and executed in memory.

T1027.013
Encrypted/Encoded File
MalwareDUSTTRAP

DUSTTRAP begins with an initial launcher that decrypts an AES-128-CFB encrypted file on disk and executes it in memory.

T1027.013
Encrypted/Encoded File
MalwareDUSTPAN

DUSTPAN decrypts an embedded payload.

T1036.004
Masquerade Task or Service
CampaignAPT41 DUST

APT41 DUST disguised DUSTPAN as a legitimate Windows binary such as `w3wp.exe` or `conn.exe`.

T1036.005
Match Legitimate Resource Name or Location
MalwareDUSTPAN

DUSTPAN is often disguised as a legitimate Windows binary such as `w3wp.exe` or `conn.exe`.

T1041
Exfiltration Over C2 Channel
MalwareDUSTTRAP

DUSTTRAP can exfiltrate collected data over C2 channels.

T1055
Process Injection
MalwareDUSTTRAP

DUSTTRAP compromises the `.text` section of a legitimate system DLL in `%windir%` to hold the contents of retrieved plug-ins.

T1055.002
Portable Executable Injection
MalwareDUSTPAN

DUSTPAN can inject its decrypted payload into another process.

T1056.001
Keylogging
MalwareDUSTTRAP

DUSTTRAP can perform keylogging operations.

T1057
Process Discovery
MalwareDUSTTRAP

DUSTTRAP can enumerate running processes.

T1059.003
Windows Command Shell
MalwareDUSTTRAP

DUSTTRAP can execute commands via `cmd.exe`.

T1070
Indicator Removal
MalwareDUSTTRAP

DUSTTRAP restores the `.text` section of compromised DLLs after malicious code is loaded into memory and before the file is closed.

T1070.004
File Deletion
CampaignAPT41 DUST

APT41 DUST deleted various artifacts from victim systems following use.

T1070.005
Network Share Connection Removal
MalwareDUSTTRAP

DUSTTRAP can remove network shares from infected systems.

T1071.001
Web Protocols
CampaignAPT41 DUST

APT41 DUST used HTTPS for command and control.

T1074.001
Local Data Staging
CampaignAPT41 DUST

APT41 DUST involved exporting data from Oracle databases to local CSV files prior to exfiltration.

T1082
System Information Discovery
MalwareDUSTTRAP

DUSTTRAP reads the value of the infected system's `HKLM\SYSTEM\Microsoft\Cryptography\MachineGUID` value.

T1083
File and Directory Discovery
MalwareDUSTTRAP

DUSTTRAP can enumerate files and directories.

T1087.001
Local Account
MalwareDUSTTRAP

DUSTTRAP can enumerate local user accounts.

T1087.002
Domain Account
MalwareDUSTTRAP

DUSTTRAP can enumerate domain accounts.

T1102
Web Service
CampaignAPT41 DUST

APT41 DUST used compromised Google Workspace accounts for command and control.

T1105
Ingress Tool Transfer
CampaignAPT41 DUST

APT41 DUST involved execution of `certutil.exe` via web shell to download the DUSTPAN dropper.

T1105
Ingress Tool Transfer
MalwareDUSTTRAP

DUSTTRAP can retrieve and load additional payloads.

T1113
Screen Capture
MalwareDUSTTRAP

DUSTTRAP can capture screenshots.

T1119
Automated Collection
CampaignAPT41 DUST

APT41 DUST used tools such as SQLULDR2 and PINEGROVE to gather local system and database information.

T1124
System Time Discovery
MalwareDUSTTRAP

DUSTTRAP reads the infected system's current time and writes it to a log file during execution.

T1135
Network Share Discovery
MalwareDUSTTRAP

DUSTTRAP can identify and enumerate victim system network shares.

T1140
Deobfuscate/Decode Files or Information
MalwareDUSTPAN

DUSTPAN decodes and decrypts embedded payloads.

T1140
Deobfuscate/Decode Files or Information
MalwareDUSTTRAP

DUSTTRAP deobfuscates embedded payloads.

T1213.006
Databases
CampaignAPT41 DUST

APT41 DUST collected data from victim Oracle databases using SQLULDR2.

T1482
Domain Trust Discovery
MalwareDUSTTRAP

DUSTTRAP can identify Active Directory information and related items.

T1497.001
System Checks
MalwareDUSTTRAP

DUSTTRAP decryption relies on the infected machine's `HKLM\SOFTWARE\Microsoft\Cryptography\MachineGUID` value.

T1505.003
Web Shell
CampaignAPT41 DUST

APT41 DUST involved use of web shells such as ANTSWORD and BLUEBEAM for persistence.

T1518.001
Security Software Discovery
MalwareDUSTTRAP

DUSTTRAP can identify security software.

T1543.003
Windows Service
MalwareDUSTPAN

DUSTPAN can persist as a Windows Service in operations.

T1543.003
Windows Service
CampaignAPT41 DUST

APT41 DUST used Windows Services with names such as `Windows Defend` for persistence of DUSTPAN.

T1553.002
Code Signing
CampaignAPT41 DUST

APT41 DUST used stolen code signing certificates for DUSTTRAP malware and subsequent payloads.

T1560.001
Archive via Utility
CampaignAPT41 DUST

APT41 DUST used `rar` to compress data downloaded from internal Oracle databases prior to exfiltration.

T1567.002
Exfiltration to Cloud Storage
CampaignAPT41 DUST

APT41 DUST exfiltrated collected information to OneDrive.

T1569.002
Service Execution
CampaignAPT41 DUST

APT41 DUST used Windows services to execute DUSTPAN.

T1573.002
Asymmetric Cryptography
CampaignAPT41 DUST

APT41 DUST used HTTPS for command and control.

T1574.001
DLL
CampaignAPT41 DUST

APT41 DUST involved the use of DLL search order hijacking to execute DUSTTRAP. APT41 DUST used also DLL side-loading to execute DUSTTRAP via an AhnLab uninstaller.

T1583.007
Serverless
CampaignAPT41 DUST

APT41 DUST used infrastructure hosted behind Cloudflare or utilized Cloudflare Workers for command and control.

Showing the first 50.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.