Tarakanov , D.. (2013, September 11). The “Kimsuky” Operation: A North Korean APT?. Retrieved August 13, 2019.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
GroupKimsuky | Kimsuky has collected Office, PDF, and HWP documents from its victims. Kimsuky has also harvested victim files through the use of the `RecentFiles()` function that collects paths of recently accessed files by parsing .lnk shortcuts from `%APPDATA%\Microsoft\Windows\Recent`. |
| T1041 Exfiltration Over C2 Channel |
GroupKimsuky | Kimsuky has exfiltrated data over its C2 channel. |
| T1055 Process Injection |
GroupKimsuky | Kimsuky has used Win7Elevate to inject malicious code into explorer.exe. |
| T1056.001 Keylogging |
GroupKimsuky | Kimsuky has used a PowerShell-based keylogger as well as a tool called MECHANICAL to log keystrokes. Kimsuky has also leveraged Native Windows API functions such as `GetAsyncKeyState()` along with others to capture keystrokes every 50 milliseconds and stores data in a file stored in the temp directory. |
| T1070.004 File Deletion |
GroupKimsuky | Kimsuky has deleted the exfiltrated data on disk after transmission. Kimsuky has also used an instrumentor script to terminate browser processes running on an infected system and then delete the cookie files on disk. Kimsuky has deleted files using the `Remove-Item` PowerShell commandlet to remove traces of executed payloads. Kimsuky has also removed remnants of files used for delivery to include .log and .zip files. |
| T1082 System Information Discovery |
GroupKimsuky | Kimsuky has enumerated OS type, OS version, and other information using a script or the "systeminfo" command. Kimsuky has also obtained system information such as OS type, OS version, and system type through querying various Windows Management Instrumentation (WMI) classes including `Win32_OperatingSystem`. |
| T1083 File and Directory Discovery |
GroupKimsuky | Kimsuky has the ability to enumerate all files and directories on an infected system. Kimsuky has used a custom script with a function called CreateFileList() that can scan all filesystem drives, prioritizing C:\Users, to locate files and file extensions of interest that ultimately generates a file called `FileList.txt` saved within the victims %TEMP% Directory that contains the findings and the respective pathways. |
| T1219.002 Remote Desktop Software |
GroupKimsuky | Kimsuky has used a modified TeamViewer client as a command and control channel. |
| T1543.003 Windows Service |
GroupKimsuky | Kimsuky has created new services for persistence. |
| T1546.001 Change Default File Association |
GroupKimsuky | Kimsuky has a HWP document stealer module which changes the default program association in the registry to open HWP documents. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupKimsuky | Kimsuky has placed scripts in the startup folder for persistence and modified the `HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce` Registry key. |
| T1560.003 Archive via Custom Method |
GroupKimsuky | Kimsuky has used RC4 encryption before exfil. |
| T1566.001 Spearphishing Attachment |
GroupKimsuky | Kimsuky has used emails containing Word, Excel and/or HWP (Hangul Word Processor) documents in their spearphishing campaigns. Kimsuky has also distributed emails with attached compressed zip files that contained malicious .LNK files masquerading as legitimate files. Kimsuky has delivered tailored PDF documents that contain malicious links. |
| T1680 Local Storage Discovery |
GroupKimsuky | Kimsuky has enumerated drives. |
| T1685 Disable or Modify Tools |
GroupKimsuky | Kimsuky has been observed turning off Windows Security Center and can hide the AV software window from the view of the infected user. |
| T1686 Disable or Modify System Firewall |
GroupKimsuky | Kimsuky has been observed disabling the system firewall. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.