ATT&CKReferencesCrowdstrike GTR2020 Mar 2020

Crowdstrike GTR2020 Mar 2020

Crowdstrike. (2020, March 2). 2020 Global Threat Report. Retrieved December 11, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples24

TechniqueUsed byProcedure example
T1008
Fallback Channels
GroupFIN7

FIN7's Harpy backdoor malware can use DNS as a backup channel for C2 if HTTP fails.

T1014
Rootkit
GroupAPT41

APT41 deployed rootkits on Linux systems.

T1021.001
Remote Desktop Protocol
GroupOilRig

OilRig has used Remote Desktop Protocol for lateral movement. The group has also used tunneling tools to tunnel RDP into the environment.

T1021.001
Remote Desktop Protocol
GroupAPT41

APT41 used RDP for lateral movement. APT41 used NATBypass to expose local RDP ports on compromised systems to the Internet.

T1021.002
SMB/Windows Admin Shares
GroupAPT41

APT41 has transferred implant files using Windows Admin Shares and the Server Message Block (SMB) protocol, then executes files through Windows Management Instrumentation (WMI).

T1053.005
Scheduled Task
GroupAPT41

APT41 used a compromised account to create a scheduled task on a system.

T1053.005
Scheduled Task
MalwareBabyShark

BabyShark has used scheduled tasks to maintain persistence.

T1059.005
Visual Basic
GroupKimsuky

Kimsuky has used Visual Basic to download malicious payloads. Kimsuky has also used malicious VBA macros within maldocs disguised as forms that trigger when a victim types any content into the lure. Kimsuky has also leveraged VBScript (VBS) scripts to execute temp.vbs every 19 minutes using a scheduled task to run QuasarRAT.

T1071.003
Mail Protocols
GroupTurla

Turla has used multiple backdoors which communicate with a C2 server via email attachments.

T1078
Valid Accounts
GroupOilRig

OilRig has used compromised credentials to access other systems on a victim network.

T1078
Valid Accounts
GroupAPT41

APT41 used compromised credentials to log on to other systems.

T1105
Ingress Tool Transfer
GroupKimsuky

Kimsuky has downloaded additional scripts, tools, and malware onto victim systems.

T1105
Ingress Tool Transfer
GroupAPT41

APT41 used certutil to download additional files. APT41 downloaded post-exploitation tools such as Cobalt Strike via command shell following initial access. APT41 has uploaded Procdump and NATBypass to a staging directory and has used these tools in follow-on activities.

T1112
Modify Registry
GroupKimsuky

Kimsuky has modified Registry settings for default file associations to enable all macros and for persistence. Kimsuky has also modified the registry entry for `HKCU:\Software\Microsoft\Windows\CurrentVersion\Run` registry key for persistence with the name WindowsSecurityCheck.

T1140
Deobfuscate/Decode Files or Information
GroupOilRig

A OilRig macro has run a PowerShell command to decode file contents. OilRig has also used certutil to decode base64-encoded files on victims.

T1195.002
Compromise Software Supply Chain
GroupCobalt Group

Cobalt Group has compromised legitimate web browser updates to deliver a backdoor.

T1197
BITS Jobs
GroupAPT41

APT41 used BITSAdmin to download and install payloads.

T1218.005
Mshta
GroupKimsuky

Kimsuky has used mshta.exe to run malicious scripts on the system.

T1218.011
Rundll32
GroupAPT41

APT41 has used rundll32.exe to execute a loader.

T1219.002
Remote Desktop Software
GroupKimsuky

Kimsuky has used a modified TeamViewer client as a command and control channel.

T1505.003
Web Shell
GroupOilRig

OilRig has used web shells, often to maintain access to a victim network.

T1547.001
Registry Run Keys / Startup Folder
GroupKimsuky

Kimsuky has placed scripts in the startup folder for persistence and modified the `HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce` Registry key.

T1574.001
DLL
GroupAPT41

APT41 has used search order hijacking to execute malicious payloads, such as Winnti for Windows. APT41 has also used legitimate executables to perform DLL side-loading of their malware.

T1574.006
Dynamic Linker Hijacking
GroupAPT41

APT41 has configured payloads to load via LD_PRELOAD.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.