Mercer, W. and Rascagneres, P. (2018, February 12). Olympic Destroyer Takes Aim At Winter Olympics. Retrieved March 14, 2019.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
MalwareOlympic Destroyer | Olympic Destroyer contains a module that tries to obtain credentials from LSASS, similar to Mimikatz. These credentials are used with PsExec and Windows Management Instrumentation to help the malware propagate itself across a network. |
| T1016 System Network Configuration Discovery |
MalwareOlympic Destroyer | Olympic Destroyer uses API calls to enumerate the infected system's ARP table. |
| T1018 Remote System Discovery |
MalwareOlympic Destroyer | Olympic Destroyer uses Windows Management Instrumentation to enumerate all systems in the network. |
| T1021.002 SMB/Windows Admin Shares |
MalwareOlympic Destroyer | Olympic Destroyer uses PsExec to interact with the |
| T1047 Windows Management Instrumentation |
MalwareOlympic Destroyer | Olympic Destroyer uses WMI to help propagate itself across a network. |
| T1135 Network Share Discovery |
MalwareOlympic Destroyer | Olympic Destroyer will attempt to enumerate mapped network shares to later attempt to wipe all files on those shares. |
| T1485 Data Destruction |
MalwareOlympic Destroyer | Olympic Destroyer overwrites files locally and on remote shares. |
| T1489 Service Stop |
MalwareOlympic Destroyer | Olympic Destroyer uses the API call |
| T1490 Inhibit System Recovery |
MalwareOlympic Destroyer | Olympic Destroyer uses the native Windows utilities |
| T1529 System Shutdown/Reboot |
MalwareOlympic Destroyer | Olympic Destroyer will shut down the compromised system after it is done modifying system configuration settings. |
| T1555.003 Credentials from Web Browsers |
MalwareOlympic Destroyer | Olympic Destroyer contains a module that tries to obtain stored credentials from web browsers. |
| T1569.002 Service Execution |
MalwareOlympic Destroyer | Olympic Destroyer utilizes PsExec to help propagate itself across a network. |
| T1570 Lateral Tool Transfer |
MalwareOlympic Destroyer | Olympic Destroyer attempts to copy itself to remote machines on the network. |
| T1685.005 Clear Windows Event Logs |
MalwareOlympic Destroyer | Olympic Destroyer will attempt to clear the System and Security event logs using |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.