Cherepanov, A.. (2016, January 3). BlackEnergy by the SSHBearDoor: attacks against Ukrainian news media and electric industry . Retrieved June 10, 2020.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1057 Process Discovery |
MalwareBlackEnergy | BlackEnergy has gathered a process list by using Tasklist.exe. |
| T1059.005 Visual Basic |
GroupSandworm Team | Sandworm Team has created VBScripts to run an SSH server. |
| T1133 External Remote Services |
GroupSandworm Team | Sandworm Team has used Dropbear SSH with a hardcoded backdoor password to maintain persistence within the target network. Sandworm Team has also used VPN tunnels established in legitimate software company infrastructure to gain access to internal networks of that software company's users. |
| T1485 Data Destruction |
MalwareBlackEnergy | BlackEnergy 2 contains a "Destroy" plug-in that destroys data stored on victim hard drives by overwriting file contents. |
| T1571 Non-Standard Port |
GroupSandworm Team | Sandworm Team has used port 6789 to accept connections on the group's SSH server. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.