ATT&CKReferencesSymantec Cicada November 2020

Symantec Cicada November 2020

Symantec. (2020, November 17). Japan-Linked Organizations Targeted in Long-Running and Sophisticated Attack Campaign. Retrieved December 17, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples14

TechniqueUsed byProcedure example
T1003.003
NTDS
GroupmenuPass

menuPass has used Ntdsutil to dump credentials.

T1005
Data from Local System
GroupmenuPass

menuPass has collected various files from the compromised computers.

T1027.013
Encrypted/Encoded File
GroupmenuPass

menuPass has encoded strings in its malware with base64 as well as with a simple, single-byte XOR obfuscation using key 0x40.

T1047
Windows Management Instrumentation
GroupmenuPass

menuPass has used a modified version of pentesting script wmiexec.vbs, which logs into a remote machine using WMI.

T1059.001
PowerShell
GroupmenuPass

menuPass uses PowerSploit to inject shellcode into PowerShell.

T1074.002
Remote Data Staging
GroupmenuPass

menuPass has staged data on remote MSP systems or other victim networks prior to exfiltration.

T1078
Valid Accounts
GroupmenuPass

menuPass has used valid accounts including shared between Managed Service Providers and clients to move between the two environments.

T1083
File and Directory Discovery
GroupmenuPass

menuPass has searched compromised systems for folders of interest including those related to HR, audit and expense, and meeting memos.

T1106
Native API
GroupmenuPass

menuPass has used native APIs including GetModuleFileName, lstrcat, CreateFile, and ReadFile.

T1119
Automated Collection
GroupmenuPass

menuPass has used the Csvde tool to collect Active Directory files and data.

T1199
Trusted Relationship
GroupmenuPass

menuPass has used legitimate access granted to Managed Service Providers in order to access victims of interest.

T1210
Exploitation of Remote Services
GroupmenuPass

menuPass has used tools to exploit the ZeroLogon vulnerability (CVE-2020-1472).

T1560.001
Archive via Utility
GroupmenuPass

menuPass has compressed files before exfiltration using TAR and RAR.

T1574.001
DLL
GroupmenuPass

menuPass has used DLL side-loading to launch versions of Mimikatz and PwDump6 as well as UPPERCUT. menuPass has also used DLL search order hijacking.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.