ATT&CKReferencesESET Telebots Dec 2016

ESET Telebots Dec 2016

Cherepanov, A.. (2016, December 13). The rise of TeleBots: Analyzing disruptive KillDisk attacks. Retrieved June 10, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples21

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupSandworm Team

Sandworm Team has used its plainpwd tool, a modified version of Mimikatz, and comsvcs.dll to dump Windows credentials from system memory.

T1018
Remote System Discovery
GroupSandworm Team

Sandworm Team has used a tool to query Active Directory using LDAP, discovering information about computers listed in AD.

T1027.010
Command Obfuscation
GroupSandworm Team

Sandworm Team has used ROT13 encoding, AES encryption and compression with the zlib library for their Python-based backdoor.

T1036.004
Masquerade Task or Service
MalwareKillDisk

KillDisk registers as a service under the Plug-And-Play Support name.

T1036.005
Match Legitimate Resource Name or Location
GroupSandworm Team

Sandworm Team has avoided detection by naming a malicious binary explorer.exe.

T1040
Network Sniffing
GroupSandworm Team

Sandworm Team has used intercepter-NG to sniff passwords in network traffic.

T1041
Exfiltration Over C2 Channel
GroupSandworm Team

Sandworm Team has sent system information to its C2 server using HTTP.

T1056.001
Keylogging
GroupSandworm Team

Sandworm Team has used a keylogger to capture keystrokes by using the SetWindowsHookEx function.

T1059.005
Visual Basic
GroupSandworm Team

Sandworm Team has created VBScripts to run an SSH server.

T1070.004
File Deletion
MalwareKillDisk

KillDisk has the ability to quit and delete itself.

T1070.004
File Deletion
GroupSandworm Team

Sandworm Team has used backdoors that can delete files used in an attack from an infected system.

T1071.001
Web Protocols
GroupSandworm Team

Sandworm Team's BCS-server tool connects to the designated C2 server via HTTP.

T1087.002
Domain Account
GroupSandworm Team

Sandworm Team has used a tool to query Active Directory using LDAP, discovering information about usernames listed in AD.

T1090
Proxy
GroupSandworm Team

Sandworm Team's BCS-server tool can create an internal proxy server to redirect traffic from the adversary-controlled C2 to internal servers which may not be connected to the internet, but are interconnected locally.

T1102.002
Bidirectional Communication
GroupSandworm Team

Sandworm Team has used the Telegram Bot API from Telegram Messenger to send and receive commands to its Python backdoor. Sandworm Team also used legitimate M.E.Doc software update check requests for sending and receiving commands and hosted malicious payloads on putdrive.com.

T1105
Ingress Tool Transfer
GroupSandworm Team

Sandworm Team has pushed additional malicious tools onto an infected system to steal user credentials, move laterally, and destroy data.

T1132.001
Standard Encoding
GroupSandworm Team

Sandworm Team's BCS-server tool uses base64 encoding and HTML tags for the communication traffic between the C2 server.

T1140
Deobfuscate/Decode Files or Information
GroupSandworm Team

Sandworm Team's VBS backdoor can decode Base64-encoded data and save it to the %TEMP% folder. The group also decrypted received information using the Triple DES algorithm and decompresses it using GZip.

T1204.002
Malicious File
GroupSandworm Team

Sandworm Team has tricked unwitting recipients into clicking on spearphishing attachments and enabling malicious macros embedded within files.

T1555.003
Credentials from Web Browsers
GroupSandworm Team

Sandworm Team's CredRaptor tool can collect saved passwords from various internet browsers.

T1566.001
Spearphishing Attachment
GroupSandworm Team

Sandworm Team has delivered malicious Microsoft Office and ZIP file attachments via spearphishing emails.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.