Mike Stokkel et al. (2024, July 18). APT41 Has Arisen From the DUST. Retrieved September 16, 2024.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareDUSTTRAP | DUSTTRAP can gather data from infected systems. |
| T1010 Application Window Discovery |
MalwareDUSTTRAP | DUSTTRAP can enumerate running application windows. |
| T1012 Query Registry |
MalwareDUSTTRAP | DUSTTRAP can enumerate Registry items. |
| T1016 System Network Configuration Discovery |
MalwareDUSTTRAP | DUSTTRAP can enumerate infected system network information. |
| T1018 Remote System Discovery |
MalwareDUSTTRAP | DUSTTRAP can use `ping` to identify remote hosts within the victim network. |
| T1027.009 Embedded Payloads |
MalwareDUSTTRAP | DUSTTRAP contains additional embedded DLLs and configuration files that are loaded into memory during execution. |
| T1027.009 Embedded Payloads |
MalwareDUSTPAN | DUSTPAN decrypts and executes an embedded payload. |
| T1027.013 Encrypted/Encoded File |
CampaignAPT41 DUST | APT41 DUST used encrypted payloads decrypted and executed in memory. |
| T1027.013 Encrypted/Encoded File |
MalwareDUSTTRAP | DUSTTRAP begins with an initial launcher that decrypts an AES-128-CFB encrypted file on disk and executes it in memory. |
| T1027.013 Encrypted/Encoded File |
MalwareDUSTPAN | DUSTPAN decrypts an embedded payload. |
| T1036.004 Masquerade Task or Service |
CampaignAPT41 DUST | APT41 DUST disguised DUSTPAN as a legitimate Windows binary such as `w3wp.exe` or `conn.exe`. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareDUSTPAN | DUSTPAN is often disguised as a legitimate Windows binary such as `w3wp.exe` or `conn.exe`. |
| T1041 Exfiltration Over C2 Channel |
MalwareDUSTTRAP | DUSTTRAP can exfiltrate collected data over C2 channels. |
| T1055 Process Injection |
MalwareDUSTTRAP | DUSTTRAP compromises the `.text` section of a legitimate system DLL in `%windir%` to hold the contents of retrieved plug-ins. |
| T1055.002 Portable Executable Injection |
MalwareDUSTPAN | DUSTPAN can inject its decrypted payload into another process. |
| T1056.001 Keylogging |
MalwareDUSTTRAP | DUSTTRAP can perform keylogging operations. |
| T1057 Process Discovery |
MalwareDUSTTRAP | DUSTTRAP can enumerate running processes. |
| T1059.003 Windows Command Shell |
MalwareDUSTTRAP | DUSTTRAP can execute commands via `cmd.exe`. |
| T1070 Indicator Removal |
MalwareDUSTTRAP | DUSTTRAP restores the `.text` section of compromised DLLs after malicious code is loaded into memory and before the file is closed. |
| T1070.004 File Deletion |
CampaignAPT41 DUST | APT41 DUST deleted various artifacts from victim systems following use. |
| T1070.005 Network Share Connection Removal |
MalwareDUSTTRAP | DUSTTRAP can remove network shares from infected systems. |
| T1071.001 Web Protocols |
CampaignAPT41 DUST | APT41 DUST used HTTPS for command and control. |
| T1074.001 Local Data Staging |
CampaignAPT41 DUST | APT41 DUST involved exporting data from Oracle databases to local CSV files prior to exfiltration. |
| T1082 System Information Discovery |
MalwareDUSTTRAP | DUSTTRAP reads the value of the infected system's `HKLM\SYSTEM\Microsoft\Cryptography\MachineGUID` value. |
| T1083 File and Directory Discovery |
MalwareDUSTTRAP | DUSTTRAP can enumerate files and directories. |
| T1087.001 Local Account |
MalwareDUSTTRAP | DUSTTRAP can enumerate local user accounts. |
| T1087.002 Domain Account |
MalwareDUSTTRAP | DUSTTRAP can enumerate domain accounts. |
| T1102 Web Service |
CampaignAPT41 DUST | APT41 DUST used compromised Google Workspace accounts for command and control. |
| T1105 Ingress Tool Transfer |
CampaignAPT41 DUST | APT41 DUST involved execution of `certutil.exe` via web shell to download the DUSTPAN dropper. |
| T1105 Ingress Tool Transfer |
MalwareDUSTTRAP | DUSTTRAP can retrieve and load additional payloads. |
| T1113 Screen Capture |
MalwareDUSTTRAP | DUSTTRAP can capture screenshots. |
| T1119 Automated Collection |
CampaignAPT41 DUST | APT41 DUST used tools such as SQLULDR2 and PINEGROVE to gather local system and database information. |
| T1124 System Time Discovery |
MalwareDUSTTRAP | DUSTTRAP reads the infected system's current time and writes it to a log file during execution. |
| T1135 Network Share Discovery |
MalwareDUSTTRAP | DUSTTRAP can identify and enumerate victim system network shares. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareDUSTPAN | DUSTPAN decodes and decrypts embedded payloads. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareDUSTTRAP | DUSTTRAP deobfuscates embedded payloads. |
| T1213.006 Databases |
CampaignAPT41 DUST | APT41 DUST collected data from victim Oracle databases using SQLULDR2. |
| T1482 Domain Trust Discovery |
MalwareDUSTTRAP | DUSTTRAP can identify Active Directory information and related items. |
| T1497.001 System Checks |
MalwareDUSTTRAP | DUSTTRAP decryption relies on the infected machine's `HKLM\SOFTWARE\Microsoft\Cryptography\MachineGUID` value. |
| T1505.003 Web Shell |
CampaignAPT41 DUST | APT41 DUST involved use of web shells such as ANTSWORD and BLUEBEAM for persistence. |
| T1518.001 Security Software Discovery |
MalwareDUSTTRAP | DUSTTRAP can identify security software. |
| T1543.003 Windows Service |
MalwareDUSTPAN | DUSTPAN can persist as a Windows Service in operations. |
| T1543.003 Windows Service |
CampaignAPT41 DUST | APT41 DUST used Windows Services with names such as `Windows Defend` for persistence of DUSTPAN. |
| T1553.002 Code Signing |
CampaignAPT41 DUST | APT41 DUST used stolen code signing certificates for DUSTTRAP malware and subsequent payloads. |
| T1560.001 Archive via Utility |
CampaignAPT41 DUST | APT41 DUST used `rar` to compress data downloaded from internal Oracle databases prior to exfiltration. |
| T1567.002 Exfiltration to Cloud Storage |
CampaignAPT41 DUST | APT41 DUST exfiltrated collected information to OneDrive. |
| T1569.002 Service Execution |
CampaignAPT41 DUST | APT41 DUST used Windows services to execute DUSTPAN. |
| T1573.002 Asymmetric Cryptography |
CampaignAPT41 DUST | APT41 DUST used HTTPS for command and control. |
| T1574.001 DLL |
CampaignAPT41 DUST | APT41 DUST involved the use of DLL search order hijacking to execute DUSTTRAP. APT41 DUST used also DLL side-loading to execute DUSTTRAP via an AhnLab uninstaller. |
| T1583.007 Serverless |
CampaignAPT41 DUST | APT41 DUST used infrastructure hosted behind Cloudflare or utilized Cloudflare Workers for command and control. |
Showing the first 50.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.