ATT&CKReferencesRostovcev APT41 2021

Rostovcev APT41 2021

Nikita Rostovcev. (2022, August 18). APT41 World Tour 2021 on a tight schedule. Retrieved February 22, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples22

TechniqueUsed byProcedure example
T1003.002
Security Account Manager
GroupAPT41

APT41 extracted user account data from the Security Account Managerr (SAM), making a copy of this database from the registry using the reg save command or by exploiting volume shadow copies.

T1003.003
NTDS
GroupAPT41

APT41 used ntdsutil to obtain a copy of the victim environment ntds.dit file.

T1012
Query Registry
GroupAPT41

APT41 queried registry values to determine items such as configured RDP ports and network configurations.

T1027.002
Software Packing
GroupAPT41

APT41 uses packers such as Themida to obfuscate malicious files.

T1030
Data Transfer Size Limits
GroupAPT41

APT41 transfers post-exploitation files dividing the payload into fixed-size chunks to evade detection.

T1033
System Owner/User Discovery
GroupAPT41

APT41 has executed whoami commands, including using the WMIEXEC utility to execute this on remote machines.

T1069
Permission Groups Discovery
GroupAPT41

APT41 used net group commands to enumerate various Windows user groups and permissions.

T1070.004
File Deletion
GroupAPT41

APT41 deleted files from the system.

T1082
System Information Discovery
GroupAPT41

APT41 uses multiple built-in commands such as systeminfo and `net config Workstation` to enumerate victim system basic configuration information.

T1087.001
Local Account
GroupAPT41

APT41 used built-in net commands to enumerate local administrator groups.

T1087.002
Domain Account
GroupAPT41

APT41 used built-in net commands to enumerate domain administrator users.

T1105
Ingress Tool Transfer
GroupAPT41

APT41 used certutil to download additional files. APT41 downloaded post-exploitation tools such as Cobalt Strike via command shell following initial access. APT41 has uploaded Procdump and NATBypass to a staging directory and has used these tools in follow-on activities.

T1190
Exploit Public-Facing Application
GroupAPT41

APT41 exploited CVE-2020-10189 against Zoho ManageEngine Desktop Central through unsafe deserialization, and CVE-2019-19781 to compromise Citrix Application Delivery Controllers (ADC) and gateway devices. APT41 leveraged vulnerabilities such as ProxyLogon exploitation or SQL injection for initial access. APT41 exploited CVE-2021-26855 against a vulnerable Microsoft Exchange Server to gain initial access to the victim network.

T1213.003
Code Repositories
GroupAPT41

APT41 cloned victim user Git repositories during intrusions.

T1550.002
Pass the Hash
GroupAPT41

APT41 uses tools such as Mimikatz to enable lateral movement via captured password hashes.

T1555
Credentials from Password Stores
GroupAPT41

APT41 has obtained information about accounts, lists of employees, and plaintext and hashed passwords from databases.

T1555.003
Credentials from Web Browsers
GroupAPT41

APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores.

T1570
Lateral Tool Transfer
GroupAPT41

APT41 uses remote shares to move and remotely execute payloads during lateral movemement.

T1595.002
Vulnerability Scanning
GroupAPT41

APT41 used the Acunetix SQL injection vulnerability scanner in target reconnaissance operations, as well as the JexBoss tool to identify vulnerabilities in Java applications.

T1595.003
Wordlist Scanning
GroupAPT41

APT41 leverages various tools and frameworks to brute-force directories on web servers.

T1596.005
Scan Databases
GroupAPT41

APT41 uses the Chinese website fofa.su, similar to the Shodan scanning service, for passive scanning of victims.

T1685
Disable or Modify Tools
GroupAPT41

APT41 developed a custom injector that enables an Event Tracing for Windows (ETW) bypass, making malicious processes invisible to Windows logging.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.