ATT&CKReferencesPaloAlto Patchwork Mar 2018

PaloAlto Patchwork Mar 2018

Levene, B. et al.. (2018, March 7). Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent. Retrieved March 31, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples12

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareBADNEWS

When it first starts, BADNEWS crawls the victim's local drives and collects documents with the following extensions: .doc, .docx, .pdf, .ppt, .pptx, and .txt.

T1036.005
Match Legitimate Resource Name or Location
MalwareBADNEWS

BADNEWS attempts to hide its payloads using legitimate filenames.

T1053.005
Scheduled Task
MalwareBADNEWS

BADNEWS creates a scheduled task to establish by executing a malicious payload every subsequent minute.

T1056.001
Keylogging
MalwareBADNEWS

When it first starts, BADNEWS spawns a new thread to log keystrokes.

T1071.001
Web Protocols
MalwareBADNEWS

BADNEWS establishes a backdoor over HTTP.

T1102.001
Dead Drop Resolver
MalwareBADNEWS

BADNEWS collects C2 information via a dead drop resolver.

T1102.002
Bidirectional Communication
MalwareBADNEWS

BADNEWS can use multiple C2 channels, including RSS feeds, Github, forums, and blogs.

T1105
Ingress Tool Transfer
MalwareBADNEWS

BADNEWS is capable of downloading additional files through C2 channels, including a new version of itself.

T1113
Screen Capture
MalwareBADNEWS

BADNEWS has a command to take a screenshot and send it to the C2 server.

T1132.001
Standard Encoding
MalwareBADNEWS

BADNEWS encodes C2 traffic with base64.

T1203
Exploitation for Client Execution
GroupPatchwork

Patchwork uses malicious documents to deliver remote execution exploits as part of. The group has previously exploited CVE-2017-8570, CVE-2012-1856, CVE-2014-4114, CVE-2017-0199, CVE-2017-11882, and CVE-2015-1641.

T1574.001
DLL
MalwareBADNEWS

BADNEWS typically loads its DLL file into a legitimate signed Java or VMware executable.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.