FireEye. (2018, October 03). APT38: Un-usual Suspects. Retrieved November 17, 2024.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.002 Software Packing |
GroupAPT38 | APT38 has used several code packing methods such as Themida, Enigma, VMProtect, and Obsidium, to pack their implants. |
| T1049 System Network Connections Discovery |
GroupAPT38 | APT38 installed a port monitoring tool, MAPMAKER, to print the active TCP connections on the local system. |
| T1056.001 Keylogging |
GroupAPT38 | APT38 used a Trojan called KEYLIME to capture keystrokes from the victim’s machine. |
| T1057 Process Discovery |
GroupAPT38 | APT38 leveraged Sysmon to understand the processes, services in the organization. |
| T1059.003 Windows Command Shell |
GroupAPT38 | APT38 has used a command-line tunneler, NACHOCHEESE, to give them shell access to a victim’s machine. Additionally, APT38 has used batch scripts. |
| T1070.004 File Deletion |
GroupAPT38 | APT38 has used a utility called CLOSESHAVE that can securely delete a file from the system. They have also removed malware, tools, or other non-native files used during the intrusion to reduce their footprint or as part of the post-intrusion cleanup process. |
| T1071.001 Web Protocols |
GroupAPT38 | APT38 used a backdoor, QUICKRIDE, to communicate to the C2 server over HTTP and HTTPS. |
| T1105 Ingress Tool Transfer |
GroupAPT38 | APT38 used a backdoor, NESTEGG, that has the capability to download and upload files to and from a victim’s machine. Additionally, APT38 has downloaded other payloads onto a victim’s machine. |
| T1112 Modify Registry |
GroupAPT38 | APT38 uses a tool called CLEANTOAD that has the capability to modify Registry keys. |
| T1115 Clipboard Data |
GroupAPT38 | APT38 used a Trojan called KEYLIME to collect data from the clipboard. |
| T1189 Drive-by Compromise |
GroupAPT38 | APT38 has conducted watering holes schemes to gain initial access to victims. |
| T1485 Data Destruction |
GroupAPT38 | APT38 has used a custom secure delete function to make deleted files unrecoverable. |
| T1486 Data Encrypted for Impact |
GroupAPT38 | APT38 has used Hermes ransomware to encrypt files with AES256. |
| T1529 System Shutdown/Reboot |
GroupAPT38 | APT38 has used a custom MBR wiper named BOOTWRECK, which will initiate a system reboot after wiping the victim's MBR. |
| T1561.002 Disk Structure Wipe |
GroupAPT38 | APT38 has used a custom MBR wiper named BOOTWRECK to render systems inoperable. |
| T1565.001 Stored Data Manipulation |
GroupAPT38 | APT38 has used DYEPACK to create, delete, and alter records in databases used for SWIFT transactions. |
| T1565.002 Transmitted Data Manipulation |
GroupAPT38 | APT38 has used DYEPACK to manipulate SWIFT messages en route to a printer. |
| T1565.003 Runtime Data Manipulation |
GroupAPT38 | APT38 has used DYEPACK.FOX to manipulate PDF data as it is accessed to remove traces of fraudulent SWIFT transactions from the data displayed to the end user. |
| T1685.005 Clear Windows Event Logs |
GroupAPT38 | APT38 clears Window Event logs and Sysmon logs from the system. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.