Dumont, R. (2019, March 20). Fake or Fake: Keeping up with OceanLotus decoys. Retrieved April 1, 2019.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1012 Query Registry |
GroupAPT32 | APT32's backdoor can query the Windows Registry to gather system information. |
| T1027.011 Fileless Storage |
GroupAPT32 | APT32's backdoor has stored its configuration in a registry key. |
| T1027.013 Encrypted/Encoded File |
GroupAPT32 | APT32 has performed code obfuscation, including encoding payloads using Base64 and using a framework called "Dont-Kill-My-Cat (DKMC). APT32 also encrypts the library used for network exfiltration with AES-256 in CBC mode in their macOS backdoor. |
| T1027.016 Junk Code Insertion |
GroupAPT32 | APT32 includes garbage code to mislead anti-malware software and researchers. |
| T1041 Exfiltration Over C2 Channel |
GroupAPT32 | APT32's backdoor has exfiltrated data using the already opened channel with its C&C server. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
GroupAPT32 | APT32's backdoor can exfiltrate data by encoding it in the subdomain field of DNS packets. |
| T1053.005 Scheduled Task |
GroupAPT32 | APT32 has used scheduled tasks to persist on victim systems. |
| T1070.006 Timestomp |
GroupAPT32 | APT32 has used scheduled task raw XML with a backdated timestamp of June 2, 2016. The group has also set the creation time of the files dropped by the second stage of the exploit to match the creation time of kernel32.dll. Additionally, APT32 has used a random value to modify the timestamp of the file storing the clientID. |
| T1082 System Information Discovery |
GroupAPT32 | APT32 has collected the OS version and computer name from victims. One of the group's backdoors can also query the Windows Registry to gather system information, and another macOS backdoor performs a fingerprint of the machine on its first connection to the C&C server. APT32 executed shellcode to identify the name of the infected host. |
| T1083 File and Directory Discovery |
GroupAPT32 | APT32's backdoor possesses the capability to list files and directories on a machine. |
| T1112 Modify Registry |
GroupAPT32 | APT32's backdoor has modified the Windows Registry to store the backdoor's configuration. |
| T1203 Exploitation for Client Execution |
GroupAPT32 | APT32 has used RTF document that includes an exploit to execute malicious code. (CVE-2017-11882) |
| T1204.002 Malicious File |
GroupAPT32 | APT32 has attempted to lure users to execute a malicious dropper delivered via a spearphishing attachment. |
| T1218.010 Regsvr32 |
GroupAPT32 | APT32 created a Scheduled Task/Job that used regsvr32.exe to execute a COM scriptlet that dynamically downloaded a backdoor and injected it into memory. The group has also used regsvr32 to run their backdoor. |
| T1543.003 Windows Service |
GroupAPT32 | APT32 modified Windows Services to ensure PowerShell scripts were loaded on the system. APT32 also creates a Windows service to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupAPT32 | APT32 established persistence using Registry Run keys, both to execute PowerShell and VBS scripts as well as to execute their backdoor directly. |
| T1560 Archive Collected Data |
GroupAPT32 | APT32's backdoor has used LZMA compression and RC4 encryption before exfiltration. |
| T1566.001 Spearphishing Attachment |
GroupAPT32 | APT32 has sent spearphishing emails with a malicious executable disguised as a document or spreadsheet. |
| T1569.002 Service Execution |
GroupAPT32 | APT32's backdoor has used Windows services as a way to execute its malicious payload. |
| T1571 Non-Standard Port |
GroupAPT32 | An APT32 backdoor can use HTTP over a non-standard TCP port (e.g 14146) which is specified in the backdoor configuration. |
| T1574.001 DLL |
GroupAPT32 | APT32 ran legitimately-signed executables from Symantec and McAfee which load a malicious DLL. The group also side-loads its backdoor by dropping a library and a legitimate, signed executable (AcroTranscoder). |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.