ATT&CKReferencesESET BlackEnergy Jan 2016

ESET BlackEnergy Jan 2016

Cherepanov, A.. (2016, January 3). BlackEnergy by the SSHBearDoor: attacks against Ukrainian news media and electric industry . Retrieved June 10, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples5

TechniqueUsed byProcedure example
T1057
Process Discovery
MalwareBlackEnergy

BlackEnergy has gathered a process list by using Tasklist.exe.

T1059.005
Visual Basic
GroupSandworm Team

Sandworm Team has created VBScripts to run an SSH server.

T1133
External Remote Services
GroupSandworm Team

Sandworm Team has used Dropbear SSH with a hardcoded backdoor password to maintain persistence within the target network. Sandworm Team has also used VPN tunnels established in legitimate software company infrastructure to gain access to internal networks of that software company's users.

T1485
Data Destruction
MalwareBlackEnergy

BlackEnergy 2 contains a "Destroy" plug-in that destroys data stored on victim hard drives by overwriting file contents.

T1571
Non-Standard Port
GroupSandworm Team

Sandworm Team has used port 6789 to accept connections on the group's SSH server.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.