KISA. (2021). Phishing Target Reconnaissance and Attack Resource Analysis Operation Muzabi. Retrieved March 8, 2024.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupKimsuky | Kimsuky has gathered credentials using Mimikatz and ProcDump. |
| T1005 Data from Local System |
MalwareAppleSeed | AppleSeed can collect data on a compromised host. |
| T1025 Data from Removable Media |
MalwareAppleSeed | AppleSeed can find and collect data from removable media devices. |
| T1030 Data Transfer Size Limits |
MalwareAppleSeed | AppleSeed has divided files if the size is 0x1000000 bytes or more. |
| T1053.005 Scheduled Task |
GroupKimsuky | Kimsuky has downloaded additional malware with scheduled tasks. Kimsuky has established persistence by creating a scheduled task named “ChromeUpdateTaskMachine” through the PowerShell cmdlet `Register-ScheduleTask` which was set to execute another PowerShell script once, then five minutes after its creation and periodically repeat every 30 minutes. Kimsuky has also set scheduled tasks that run periodically using the PT1M repetition pattern leveraging naming conventions of Anti-Virus software to include "AhnlabUpdate". |
| T1056.001 Keylogging |
MalwareAppleSeed | AppleSeed can use |
| T1056.001 Keylogging |
GroupKimsuky | Kimsuky has used a PowerShell-based keylogger as well as a tool called MECHANICAL to log keystrokes. Kimsuky has also leveraged Native Windows API functions such as `GetAsyncKeyState()` along with others to capture keystrokes every 50 milliseconds and stores data in a file stored in the temp directory. |
| T1059.001 PowerShell |
GroupKimsuky | Kimsuky has executed a variety of PowerShell scripts including Invoke-Mimikatz. Kimsuky has also utilized PowerShell scripts for execution, persistence, and defense evasion. Kimsuky has leveraged PowerShell’s cmdlet `Expand-Archive` to extract contents of zip files into the same directory. Kimsuky has employed ClickFix type tactics enticing victims to copy and paste malicious PowerShell commands and scripts, where the scripts ultimately led to QuasarRAT. |
| T1059.003 Windows Command Shell |
GroupKimsuky | Kimsuky has executed Windows commands by using `cmd` and running batch scripts. Kimsuky has also used `cmd.exe` to automatically open downloaded decoy pdf documents with the system’s default PDF viewer. Kimsuky has utilized malicious payloads to create reverse shells within the victim environment. Kimsuky has also used batch scripts to eventually run QuasarRAT. |
| T1059.006 Python |
GroupKimsuky | Kimsuky has used a macOS Python implant to gather data as well as MailFetcher.py code to automatically collect email data. |
| T1070.004 File Deletion |
GroupKimsuky | Kimsuky has deleted the exfiltrated data on disk after transmission. Kimsuky has also used an instrumentor script to terminate browser processes running on an infected system and then delete the cookie files on disk. Kimsuky has deleted files using the `Remove-Item` PowerShell commandlet to remove traces of executed payloads. Kimsuky has also removed remnants of files used for delivery to include .log and .zip files. |
| T1071.001 Web Protocols |
MalwareAppleSeed | AppleSeed has the ability to communicate with C2 over HTTP. |
| T1083 File and Directory Discovery |
GroupKimsuky | Kimsuky has the ability to enumerate all files and directories on an infected system. Kimsuky has used a custom script with a function called CreateFileList() that can scan all filesystem drives, prioritizing C:\Users, to locate files and file extensions of interest that ultimately generates a file called `FileList.txt` saved within the victims %TEMP% Directory that contains the findings and the respective pathways. |
| T1098.007 Additional Local or Domain Groups |
GroupKimsuky | Kimsuky has added accounts to specific groups with |
| T1111 Multi-Factor Authentication Interception |
GroupKimsuky | Kimsuky has used a proprietary tool to intercept one time passwords required for two-factor authentication. |
| T1112 Modify Registry |
GroupKimsuky | Kimsuky has modified Registry settings for default file associations to enable all macros and for persistence. Kimsuky has also modified the registry entry for `HKCU:\Software\Microsoft\Windows\CurrentVersion\Run` registry key for persistence with the name WindowsSecurityCheck. |
| T1113 Screen Capture |
MalwareAppleSeed | AppleSeed can take screenshots on a compromised host by calling a series of APIs. |
| T1114.002 Remote Email Collection |
GroupKimsuky | Kimsuky has used tools such as the MailFetch mail crawler to collect victim emails (excluding spam) from online services via IMAP. |
| T1119 Automated Collection |
MalwareAppleSeed | AppleSeed has automatically collected data from USB drives, keystrokes, and screen images before exfiltration. |
| T1136.001 Local Account |
GroupKimsuky | Kimsuky has created accounts with |
| T1190 Exploit Public-Facing Application |
GroupKimsuky | Kimsuky has exploited various vulnerabilities for initial access, including Microsoft Exchange vulnerability CVE-2020-0688. |
| T1204.001 Malicious Link |
GroupKimsuky | Kimsuky has lured victims into clicking malicious links. |
| T1218.005 Mshta |
GroupKimsuky | Kimsuky has used mshta.exe to run malicious scripts on the system. |
| T1218.010 Regsvr32 |
GroupKimsuky | Kimsuky has executed malware with |
| T1518.001 Security Software Discovery |
GroupKimsuky | Kimsuky has checked for the presence of antivirus software with |
| T1534 Internal Spearphishing |
GroupKimsuky | Kimsuky has sent internal spearphishing emails for lateral movement after stealing victim information. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupKimsuky | Kimsuky has placed scripts in the startup folder for persistence and modified the `HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce` Registry key. |
| T1560 Archive Collected Data |
MalwareAppleSeed | AppleSeed has compressed collected data before exfiltration. |
| T1564.002 Hidden Users |
GroupKimsuky | Kimsuky has run |
| T1566.001 Spearphishing Attachment |
GroupKimsuky | Kimsuky has used emails containing Word, Excel and/or HWP (Hangul Word Processor) documents in their spearphishing campaigns. Kimsuky has also distributed emails with attached compressed zip files that contained malicious .LNK files masquerading as legitimate files. Kimsuky has delivered tailored PDF documents that contain malicious links. |
| T1566.002 Spearphishing Link |
GroupKimsuky | Kimsuky has sent spearphishing emails containing a link to a document that contained malicious macros or took the victim to an actor-controlled domain. |
| T1567 Exfiltration Over Web Service |
MalwareAppleSeed | AppleSeed has exfiltrated files using web services. |
| T1583.001 Domains |
GroupKimsuky | Kimsuky has registered domains to spoof targeted organizations and trusted third parties including search engines, web platforms, and cryptocurrency exchanges. |
| T1583.004 Server |
GroupKimsuky | Kimsuky has purchased hosting servers with virtual currency and prepaid cards. |
| T1584.001 Domains |
GroupKimsuky | Kimsuky has compromised legitimate sites and used them to distribute malware. |
| T1585.001 Social Media Accounts |
GroupKimsuky | Kimsuky has created social media accounts to monitor news and security trends as well as potential targets. |
| T1585.002 Email Accounts |
GroupKimsuky | Kimsuky has created email accounts for phishing operations. |
| T1587.001 Malware |
GroupKimsuky | Kimsuky has developed its own unique malware such as MailFetch.py for use in operations. |
| T1588.005 Exploits |
GroupKimsuky | Kimsuky has obtained exploit code for various CVEs. |
| T1589.003 Employee Names |
GroupKimsuky | Kimsuky has collected victim employee name information. |
| T1591 Gather Victim Org Information |
GroupKimsuky | Kimsuky has collected victim organization information including but not limited to organization hierarchy, functions, press releases, and others. Kimsuky has also used large language models (LLMs) to gather information about potential targets of interest. |
| T1593.002 Search Engines |
GroupKimsuky | Kimsuky has searched for vulnerabilities, tools, and geopolitical trends on Google to target victims. |
| T1594 Search Victim-Owned Websites |
GroupKimsuky | Kimsuky has searched for information on the target company's website. |
| T1598.003 Spearphishing Link |
GroupKimsuky | Kimsuky has used links in e-mail to steal account information including web beacons for target profiling. Kimsuky has also utilized QR codes (also known as Quishing) to direct victims to malicious links through the reliance of a mobile device to scan a code with an embedded malicious URL. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.