ATT&CKReferencesESET OceanLotus Mar 2019

ESET OceanLotus Mar 2019

Dumont, R. (2019, March 20). Fake or Fake: Keeping up with OceanLotus decoys. Retrieved April 1, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples21

TechniqueUsed byProcedure example
T1012
Query Registry
GroupAPT32

APT32's backdoor can query the Windows Registry to gather system information.

T1027.011
Fileless Storage
GroupAPT32

APT32's backdoor has stored its configuration in a registry key.

T1027.013
Encrypted/Encoded File
GroupAPT32

APT32 has performed code obfuscation, including encoding payloads using Base64 and using a framework called "Dont-Kill-My-Cat (DKMC). APT32 also encrypts the library used for network exfiltration with AES-256 in CBC mode in their macOS backdoor.

T1027.016
Junk Code Insertion
GroupAPT32

APT32 includes garbage code to mislead anti-malware software and researchers.

T1041
Exfiltration Over C2 Channel
GroupAPT32

APT32's backdoor has exfiltrated data using the already opened channel with its C&C server.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
GroupAPT32

APT32's backdoor can exfiltrate data by encoding it in the subdomain field of DNS packets.

T1053.005
Scheduled Task
GroupAPT32

APT32 has used scheduled tasks to persist on victim systems.

T1070.006
Timestomp
GroupAPT32

APT32 has used scheduled task raw XML with a backdated timestamp of June 2, 2016. The group has also set the creation time of the files dropped by the second stage of the exploit to match the creation time of kernel32.dll. Additionally, APT32 has used a random value to modify the timestamp of the file storing the clientID.

T1082
System Information Discovery
GroupAPT32

APT32 has collected the OS version and computer name from victims. One of the group's backdoors can also query the Windows Registry to gather system information, and another macOS backdoor performs a fingerprint of the machine on its first connection to the C&C server. APT32 executed shellcode to identify the name of the infected host.

T1083
File and Directory Discovery
GroupAPT32

APT32's backdoor possesses the capability to list files and directories on a machine.

T1112
Modify Registry
GroupAPT32

APT32's backdoor has modified the Windows Registry to store the backdoor's configuration.

T1203
Exploitation for Client Execution
GroupAPT32

APT32 has used RTF document that includes an exploit to execute malicious code. (CVE-2017-11882)

T1204.002
Malicious File
GroupAPT32

APT32 has attempted to lure users to execute a malicious dropper delivered via a spearphishing attachment.

T1218.010
Regsvr32
GroupAPT32

APT32 created a Scheduled Task/Job that used regsvr32.exe to execute a COM scriptlet that dynamically downloaded a backdoor and injected it into memory. The group has also used regsvr32 to run their backdoor.

T1543.003
Windows Service
GroupAPT32

APT32 modified Windows Services to ensure PowerShell scripts were loaded on the system. APT32 also creates a Windows service to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupAPT32

APT32 established persistence using Registry Run keys, both to execute PowerShell and VBS scripts as well as to execute their backdoor directly.

T1560
Archive Collected Data
GroupAPT32

APT32's backdoor has used LZMA compression and RC4 encryption before exfiltration.

T1566.001
Spearphishing Attachment
GroupAPT32

APT32 has sent spearphishing emails with a malicious executable disguised as a document or spreadsheet.

T1569.002
Service Execution
GroupAPT32

APT32's backdoor has used Windows services as a way to execute its malicious payload.

T1571
Non-Standard Port
GroupAPT32

An APT32 backdoor can use HTTP over a non-standard TCP port (e.g 14146) which is specified in the backdoor configuration.

T1574.001
DLL
GroupAPT32

APT32 ran legitimately-signed executables from Symantec and McAfee which load a malicious DLL. The group also side-loads its backdoor by dropping a library and a legitimate, signed executable (AcroTranscoder).

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.