Settle, A., et al. (2016, August 8). MONSOON - Analysis Of An APT Campaign. Retrieved September 22, 2016.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareBADNEWS | When it first starts, BADNEWS crawls the victim's local drives and collects documents with the following extensions: .doc, .docx, .pdf, .ppt, .pptx, and .txt. |
| T1016 System Network Configuration Discovery |
MalwareUnknown Logger | Unknown Logger can obtain information about the victim's IP address. |
| T1020 Automated Exfiltration |
MalwareTINYTYPHON | When a document is found matching one of the extensions in the configuration, TINYTYPHON uploads it to the C2 server. |
| T1027.013 Encrypted/Encoded File |
MalwareTINYTYPHON | TINYTYPHON has used XOR with 0x90 to obfuscate its configuration file. |
| T1033 System Owner/User Discovery |
MalwareUnknown Logger | Unknown Logger can obtain information about the victim usernames. |
| T1039 Data from Network Shared Drive |
MalwareBADNEWS | When it first starts, BADNEWS crawls the victim's mapped drives and collects documents with the following extensions: .doc, .docx, .pdf, .ppt, .pptx, and .txt. |
| T1055.012 Process Hollowing |
MalwareBADNEWS | BADNEWS has a command to download an .exe and use process hollowing to inject it into a new process. |
| T1056.001 Keylogging |
MalwareBADNEWS | When it first starts, BADNEWS spawns a new thread to log keystrokes. |
| T1056.001 Keylogging |
MalwareUnknown Logger | Unknown Logger is capable of recording keystrokes. |
| T1059.001 PowerShell |
MalwareAutoIt backdoor | AutoIt backdoor downloads a PowerShell script that decodes to a typical shellcode loader. |
| T1059.003 Windows Command Shell |
MalwareBADNEWS | BADNEWS is capable of executing commands via cmd.exe. |
| T1074.001 Local Data Staging |
MalwareBADNEWS | BADNEWS copies documents under 15MB found on the victim system to is the user's |
| T1082 System Information Discovery |
MalwareUnknown Logger | Unknown Logger can obtain information about the victim computer name, physical memory, country, and date. |
| T1083 File and Directory Discovery |
MalwareTINYTYPHON | TINYTYPHON searches through the drive containing the OS, then all drive letters C through to Z, for documents matching certain extensions. |
| T1083 File and Directory Discovery |
MalwareAutoIt backdoor | AutoIt backdoor is capable of identifying documents on the victim with the following extensions: .doc; .pdf, .csv, .ppt, .docx, .pst, .xls, .xlsx, .pptx, and .jpeg. |
| T1091 Replication Through Removable Media |
MalwareUnknown Logger | Unknown Logger is capable of spreading to USB devices. |
| T1102.001 Dead Drop Resolver |
MalwareBADNEWS | BADNEWS collects C2 information via a dead drop resolver. |
| T1102.002 Bidirectional Communication |
MalwareBADNEWS | BADNEWS can use multiple C2 channels, including RSS feeds, Github, forums, and blogs. |
| T1105 Ingress Tool Transfer |
MalwareUnknown Logger | Unknown Logger is capable of downloading remote files. |
| T1105 Ingress Tool Transfer |
MalwareBADNEWS | BADNEWS is capable of downloading additional files through C2 channels, including a new version of itself. |
| T1106 Native API |
MalwareBADNEWS | BADNEWS has a command to download an .exe and execute it via CreateProcess API. It can also run with ShellExecute. |
| T1113 Screen Capture |
MalwareBADNEWS | BADNEWS has a command to take a screenshot and send it to the C2 server. |
| T1120 Peripheral Device Discovery |
MalwareBADNEWS | BADNEWS checks for new hard drives on the victim, such as USB devices, by listening for the WM_DEVICECHANGE window message. |
| T1132 Data Encoding |
MalwareBADNEWS | After encrypting C2 data, BADNEWS converts it into a hexadecimal representation and then encodes it into base64. |
| T1132.001 Standard Encoding |
MalwareBADNEWS | BADNEWS encodes C2 traffic with base64. |
| T1132.001 Standard Encoding |
MalwareAutoIt backdoor | AutoIt backdoor has sent a C2 response that was base64-encoded. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareTINYTYPHON | TINYTYPHON installs itself under Registry Run key to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareBADNEWS | BADNEWS installs a registry Run key to establish persistence. |
| T1548.002 Bypass User Account Control |
MalwareAutoIt backdoor | AutoIt backdoor attempts to escalate privileges by bypassing User Access Control. |
| T1555.003 Credentials from Web Browsers |
MalwareUnknown Logger | Unknown Logger is capable of stealing usernames and passwords from browsers on the victim machine. |
| T1573.001 Symmetric Cryptography |
MalwareBADNEWS | BADNEWS encrypts C2 data with a ROR by 3 and an XOR by 0x23. |
| T1574.001 DLL |
MalwareBADNEWS | BADNEWS typically loads its DLL file into a legitimate signed Java or VMware executable. |
| T1685 Disable or Modify Tools |
MalwareUnknown Logger | Unknown Logger has functionality to disable security tools, including Kaspersky, BitDefender, and MalwareBytes. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.