Unit 42. (2022, December 20). Russia’s Trident Ursa (aka Gamaredon APT) Cyber Conflict Operations Unwavering Since Invasion of Ukraine. Retrieved September 12, 2024.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1001 Data Obfuscation |
GroupGamaredon Group | Gamaredon Group has used obfuscated VBScripts with randomly generated variable names and concatenated strings. |
| T1047 Windows Management Instrumentation |
GroupGamaredon Group | Gamaredon Group has used WMI to execute scripts used for discovery and for determining the C2 IP address. Gamaredon Group has used the following WMI query to search for a ping record: `Select * From Win32_PingStatus where Address = 'mil.gov.ua'`. |
| T1053.005 Scheduled Task |
GroupGamaredon Group | Gamaredon Group has created scheduled tasks to launch executables after a designated number of minutes have passed. |
| T1071.001 Web Protocols |
GroupGamaredon Group | Gamaredon Group has used HTTP and HTTPS for C2 communications. |
| T1102.003 One-Way Communication |
GroupGamaredon Group | Gamaredon Group has used Telegram Messenger content to discover the IP address for C2 communications. |
| T1105 Ingress Tool Transfer |
GroupGamaredon Group | Gamaredon Group has downloaded additional malware and tools onto a compromised host. For example, Gamaredon Group uses a backdoor script to retrieve and decode additional payloads once in victim environments. |
| T1140 Deobfuscate/Decode Files or Information |
GroupGamaredon Group | Gamaredon Group tools decrypted additional payloads from the C2. Gamaredon Group has also decoded Base64-encoded source code of a downloader. Additionally, Gamaredon Group has decoded Telegram content to reveal the IP address for C2 communications. |
| T1204.001 Malicious Link |
GroupGamaredon Group | Gamaredon Group has attempted to get users to click on a link pointing to a malicious HTML file leading to follow-on malicious content. |
| T1204.002 Malicious File |
GroupGamaredon Group | Gamaredon Group has attempted to get users to click on Office attachments with malicious macros embedded. Gamaredon Group has also attempted to get users to click on thematically named files. |
| T1218.005 Mshta |
GroupGamaredon Group | Gamaredon Group has used `mshta.exe` to execute malicious files. |
| T1480 Execution Guardrails |
GroupGamaredon Group | Gamaredon Group has used geoblocking to limit downloads of the malicious file to specific geographic locations. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupGamaredon Group | Gamaredon Group tools have registered Run keys in the registry to give malicious VBS files persistence. |
| T1566.001 Spearphishing Attachment |
GroupGamaredon Group | Gamaredon Group has delivered spearphishing emails with malicious attachments to targets. Additionally, Gamaredon Group has distributed malicious LNK files compressed in ZIP archives. |
| T1568.001 Fast Flux DNS |
GroupGamaredon Group | Gamaredon Group has used fast flux DNS to mask their command and control channel behind rotating IP addresses. Additionally, Gamaredon Group has used a low-frequency variant of the single-flux method. |
| T1583.003 Virtual Private Server |
GroupGamaredon Group | Gamaredon Group has used VPS hosting providers for infrastructure outside of Russia. |
| T1588.002 Tool |
GroupGamaredon Group | Gamaredon Group has used various legitimate tools, such as `mshta.exe` and Reg, and services during operations. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.