Adamitis, D. et al. (2019, June 4). It's alive: Threat actors cobble together open-source pieces into monstrous Frankenstein campaign. Retrieved May 11, 2020.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
CampaignFrankenstein | During Frankenstein, the threat actors used Empire to gather various local system information. |
| T1016 System Network Configuration Discovery |
ToolEmpire | Empire can acquire network configuration information like DNS servers, public IP, and network proxies used by a host. |
| T1016 System Network Configuration Discovery |
CampaignFrankenstein | During Frankenstein, the threat actors used Empire to find the public IP address of a compromised system. |
| T1020 Automated Exfiltration |
ToolEmpire | Empire has the ability to automatically send collected data back to the threat actors' C2. |
| T1020 Automated Exfiltration |
CampaignFrankenstein | During Frankenstein, the threat actors collected information via Empire, which was automatically sent back to the adversary's C2. |
| T1027.010 Command Obfuscation |
CampaignFrankenstein | During Frankenstein, the threat actors ran encoded commands from the command line. |
| T1033 System Owner/User Discovery |
CampaignFrankenstein | During Frankenstein, the threat actors used Empire to enumerate hosts and gather username, machine name, and administrative permissions information. |
| T1033 System Owner/User Discovery |
ToolEmpire | Empire can enumerate the username on targeted hosts. |
| T1036.004 Masquerade Task or Service |
CampaignFrankenstein | During Frankenstein, the threat actors named a malicious scheduled task "WinUpdate" for persistence. |
| T1041 Exfiltration Over C2 Channel |
CampaignFrankenstein | During Frankenstein, the threat actors collected information via Empire, which sent the data back to the adversary's C2. |
| T1041 Exfiltration Over C2 Channel |
ToolEmpire | Empire can send data gathered from a target through the command and control channel. |
| T1047 Windows Management Instrumentation |
CampaignFrankenstein | During Frankenstein, the threat actors used WMI queries to check if various security applications were running as well as to determine the operating system version. |
| T1053.005 Scheduled Task |
CampaignFrankenstein | During Frankenstein, the threat actors established persistence through a scheduled task using the command: `/Create /F /SC DAILY /ST 09:00 /TN WinUpdate /TR`, named "WinUpdate" |
| T1057 Process Discovery |
ToolEmpire | Empire can find information about processes running on local and remote systems. |
| T1057 Process Discovery |
CampaignFrankenstein | During Frankenstein, the threat actors used Empire to obtain a list of all running processes. |
| T1059.001 PowerShell |
CampaignFrankenstein | During Frankenstein, the threat actors used PowerShell to run a series of Base64-encoded commands that acted as a stager and enumerated hosts. |
| T1059.003 Windows Command Shell |
CampaignFrankenstein | During Frankenstein, the threat actors ran a command script to set up persistence as a scheduled task named "WinUpdate", as well as other encoded commands from the command-line |
| T1059.005 Visual Basic |
CampaignFrankenstein | During Frankenstein, the threat actors used Word documents that prompted the victim to enable macros and run a Visual Basic script. |
| T1071.001 Web Protocols |
CampaignFrankenstein | During Frankenstein, the threat actors used HTTP GET requests for C2. |
| T1082 System Information Discovery |
CampaignFrankenstein | During Frankenstein, the threat actors used Empire to obtain the compromised machine's name. |
| T1082 System Information Discovery |
ToolEmpire | Empire can enumerate host system information like OS, architecture, domain name, applied patches, and more. |
| T1105 Ingress Tool Transfer |
CampaignFrankenstein | During Frankenstein, the threat actors downloaded files and tools onto a victim machine. |
| T1119 Automated Collection |
ToolEmpire | Empire can automatically gather the username, domain name, machine name, and other information from a compromised system. |
| T1119 Automated Collection |
CampaignFrankenstein | During Frankenstein, the threat actors used Empire to automatically gather the username, domain name, machine name, and other system information. |
| T1127.001 MSBuild |
CampaignFrankenstein | During Frankenstein, the threat actors used MSbuild to execute an actor-created file. |
| T1140 Deobfuscate/Decode Files or Information |
CampaignFrankenstein | During Frankenstein, the threat actors deobfuscated Base64-encoded commands following the execution of a malicious script, which revealed a small script designed to obtain an additional payload. |
| T1203 Exploitation for Client Execution |
CampaignFrankenstein | During Frankenstein, the threat actors exploited CVE-2017-11882 to execute code on the victim's machine. |
| T1204.002 Malicious File |
CampaignFrankenstein | During Frankenstein, the threat actors relied on a victim to enable macros within a malicious Microsoft Word document likely sent via email. |
| T1221 Template Injection |
CampaignFrankenstein | During Frankenstein, the threat actors used trojanized documents that retrieved remote templates from an adversary-controlled website. |
| T1497.001 System Checks |
CampaignFrankenstein | During Frankenstein, the threat actors used a script that ran WMI queries to check if a VM or sandbox was running, including VMWare and Virtualbox. The script would also call WMI to determine the number of cores allocated to the system; if less than two the script would stop execution. |
| T1518.001 Security Software Discovery |
CampaignFrankenstein | During Frankenstein, the threat actors used WMI queries to determine if analysis tools were running on a compromised system. |
| T1566.001 Spearphishing Attachment |
CampaignFrankenstein | During Frankenstein, the threat actors likely used spearphishing emails to send malicious Microsoft Word documents. |
| T1573.001 Symmetric Cryptography |
CampaignFrankenstein | During Frankenstein, the threat actors communicated with C2 via an encrypted RC4 byte stream and AES-CBC. |
| T1588.002 Tool |
CampaignFrankenstein | For Frankenstein, the threat actors obtained and used Empire. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.