ATT&CKReferencesFireEye APT29 Nov 2018

FireEye APT29 Nov 2018

Dunwoody, M., et al. (2018, November 19). Not So Cozy: An Uncomfortable Examination of a Suspected APT29 Phishing Campaign. Retrieved November 27, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns1

Procedure examples13

TechniqueUsed byProcedure example
T1027.010
Command Obfuscation
CampaignC0021

During C0021, the threat actors used encoded PowerShell commands.

T1059.001
PowerShell
CampaignC0021

During C0021, the threat actors used obfuscated PowerShell to extract an encoded payload from within an .LNK file.

T1071.001
Web Protocols
CampaignC0021

During C0021, the threat actors used HTTP for some of their C2 communications.

T1095
Non-Application Layer Protocol
CampaignC0021

During C0021, the threat actors used TCP for some C2 communications.

T1105
Ingress Tool Transfer
CampaignC0021

During C0021, the threat actors downloaded additional tools and files onto victim machines.

T1140
Deobfuscate/Decode Files or Information
CampaignC0021

During C0021, the threat actors deobfuscated encoded PowerShell commands including use of the specific string `'FromBase'+0x40+'String'`, in place of `FromBase64String` which is normally used to decode base64.

T1204.001
Malicious Link
CampaignC0021

During C0021, the threat actors lured users into clicking a malicious link which led to the download of a ZIP archive containing a malicious .LNK file.

T1218.011
Rundll32
CampaignC0021

During C0021, the threat actors used `rundll32.exe` to execute the Cobalt Strike Beacon loader DLL.

T1566.002
Spearphishing Link
CampaignC0021

During C0021, the threat actors sent phishing emails with unique malicious links, likely for tracking victim clicks.

T1573.002
Asymmetric Cryptography
CampaignC0021

During C0021, the threat actors used SSL via TCP port 443 for C2 communications.

T1583.001
Domains
CampaignC0021

For C0021, the threat actors registered domains for use in C2.

T1588.002
Tool
CampaignC0021

For C0021, the threat actors used Cobalt Strike configured with a modified variation of the publicly available Pandora Malleable C2 Profile.

T1608.001
Upload Malware
CampaignC0021

For C0021, the threat actors uploaded malware to websites under their control.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.