ATT&CKReferencesUnit42 Sofacy Dec 2018

Unit42 Sofacy Dec 2018

Lee, B., Falcone, R. (2018, December 12). Dear Joohn: The Sofacy Group’s Global Campaign. Retrieved April 19, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software2

Campaigns0

None recorded.

Procedure examples12

TechniqueUsed byProcedure example
T1027.002
Software Packing
MalwareZebrocy

Zebrocy's Delphi variant was packed with UPX.

T1047
Windows Management Instrumentation
MalwareZebrocy

One variant of Zebrocy uses WMI queries to gather information.

T1057
Process Discovery
MalwareCannon

Cannon can obtain a list of processes running on the system.

T1057
Process Discovery
MalwareZebrocy

Zebrocy uses the tasklist and wmic process get Capture, ExecutablePath commands to gather the processes running on the system.

T1071.001
Web Protocols
MalwareZebrocy

Zebrocy uses HTTP for C2.

T1071.003
Mail Protocols
MalwareZebrocy

Zebrocy uses SMTP and POP3 for C2.

T1082
System Information Discovery
MalwareCannon

Cannon can gather system information from the victim’s machine such as the OS version, and machine name.

T1082
System Information Discovery
MalwareZebrocy

Zebrocy collects the OS version and computer name. Zebrocy also runs the systeminfo command to gather system information.

T1113
Screen Capture
MalwareZebrocy

A variant of Zebrocy captures screenshots of the victim’s machine in JPEG and BMP format.

T1221
Template Injection
GroupAPT28

APT28 used weaponized Microsoft Word documents abusing the remote template function to retrieve a malicious macro.

T1680
Local Storage Discovery
MalwareCannon

Cannon can gather drive information from the victim's machine.

T1680
Local Storage Discovery
MalwareZebrocy

Zebrocy collects the serial number for the storage volume C:\.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.