CISA. (2022, September 23). AA22-264A Iranian State Actors Conduct Cyber Operations Against the Government of Albania. Retrieved August 6, 2024.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
CampaignHomeLand Justice | During HomeLand Justice, threat actors dumped LSASS memory on compromised hosts. |
| T1021.001 Remote Desktop Protocol |
CampaignHomeLand Justice | During HomeLand Justice, threat actors primarily used RDP for lateral movement in the victim environment. |
| T1021.002 SMB/Windows Admin Shares |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used SMB for lateral movement. |
| T1027.013 Encrypted/Encoded File |
MalwareROADSWEEP | The ROADSWEEP binary contains RC4 encrypted embedded scripts. |
| T1036.005 Match Legitimate Resource Name or Location |
CampaignHomeLand Justice | During HomeLand Justice, threat actors renamed ROADSWEEP to GoXML.exe and ZeroCleare to cl.exe. |
| T1041 Exfiltration Over C2 Channel |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used HTTP to transfer data from compromised Exchange servers. |
| T1046 Network Service Discovery |
CampaignHomeLand Justice | During HomeLand Justice, threat actors executed the Advanced Port Scanner tool on compromised systems. |
| T1059.001 PowerShell |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used PowerShell cmdlets New-MailboxSearch and Get-Recipient for discovery. |
| T1059.003 Windows Command Shell |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used Windows batch files for persistence and execution. |
| T1070.004 File Deletion |
MalwareZeroCleare | ZeroCleare has the ability to uninstall the RawDisk driver and delete the `rwdsk` file on disk. |
| T1078 Valid Accounts |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used a compromised Exchange account to search mailboxes and create new Exchange accounts. |
| T1083 File and Directory Discovery |
MalwareROADSWEEP | ROADSWEEP can enumerate files on infected devices and avoid encrypting files with .exe, .dll, .sys, .lnk, or . lck extensions. |
| T1087.003 Email Account |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used compromised Exchange accounts to search mailboxes for administrator accounts. |
| T1114.002 Remote Email Collection |
CampaignHomeLand Justice | During HomeLand Justice, threat actors made multiple HTTP POST requests to the Exchange servers of the victim organization to transfer data. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareROADSWEEP | ROADSWEEP can decrypt embedded scripts prior to execution. |
| T1190 Exploit Public-Facing Application |
CampaignHomeLand Justice | For HomeLand Justice, threat actors exploited CVE-2019-0604 in Microsoft SharePoint for initial access. |
| T1480 Execution Guardrails |
MalwareROADSWEEP | ROADSWEEP requires four command line arguments to execute correctly, otherwise it will produce a message box and halt execution. |
| T1486 Data Encrypted for Impact |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used ROADSWEEP ransomware to encrypt files on targeted systems. |
| T1486 Data Encrypted for Impact |
MalwareROADSWEEP | ROADSWEEP can RC4 encrypt content in blocks on targeted systems. |
| T1490 Inhibit System Recovery |
MalwareROADSWEEP | ROADSWEEP has the ability to disable `SystemRestore` and Volume Shadow Copies. |
| T1505.003 Web Shell |
CampaignHomeLand Justice | For HomeLand Justice, threat actors used .aspx webshells named pickers.aspx, error4.aspx, and ClientBin.aspx, to maintain persistence. |
| T1553.002 Code Signing |
MalwareROADSWEEP | ROADSWEEP has been digitally signed with a certificate issued to the Kuwait Telecommunications Company KSC. |
| T1561.002 Disk Structure Wipe |
MalwareZeroCleare | ZeroCleare can corrupt the file system and wipe the system drive on targeted hosts. |
| T1561.002 Disk Structure Wipe |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used a version of ZeroCleare to wipe disk drives on targeted hosts. |
| T1570 Lateral Tool Transfer |
CampaignHomeLand Justice | During HomeLand Justice, threat actors initiated a process named Mellona.exe to spread the ROADSWEEP file encryptor and a persistence script to a list of internal machines. |
| T1588.002 Tool |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used tools including Advanced Port Scanner, Mimikatz, and Impacket. |
| T1588.003 Code Signing Certificates |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used tools with legitimate code signing certificates. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.