ATT&CKReferencesNovetta Blockbuster

Novetta Blockbuster

Novetta Threat Research Group. (2016, February 24). Operation Blockbuster: Unraveling the Long Thread of the Sony Attack. Retrieved February 25, 2016.

Open the source

Techniques3

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples36

TechniqueUsed byProcedure example
T1001.003
Protocol or Service Impersonation
GroupLazarus Group

Lazarus Group malware also uses a unique form of communication encryption known as FakeTLS that mimics TLS but uses a different encryption method, potentially evading SSL traffic inspection/decryption.

T1005
Data from Local System
GroupLazarus Group

Lazarus Group has collected data and files from compromised networks.

T1008
Fallback Channels
GroupLazarus Group

Lazarus Group malware SierraAlfa sends data to one of the hard-coded C2 servers chosen at random, and if the transmission fails, chooses a new C2 server to attempt the transmission again.

T1010
Application Window Discovery
GroupLazarus Group

Lazarus Group malware IndiaIndia obtains and sends to its C2 server the title of the window for each running process. The KilaAlfa keylogger also reports the title of the window in the foreground.

T1012
Query Registry
GroupLazarus Group

Lazarus Group malware IndiaIndia checks Registry keys within HKCU and HKLM to determine if certain applications are present, including SecureCRT, Terminal Services, RealVNC, TightVNC, UltraVNC, Radmin, mRemote, TeamViewer, FileZilla, pcAnyware, and Remote Desktop. Another Lazarus Group malware sample checks for the presence of the following Registry key:HKEY_CURRENT_USER\Software\Bitcoin\Bitcoin-Qt.

T1016
System Network Configuration Discovery
GroupLazarus Group

Lazarus Group malware IndiaIndia obtains and sends to its C2 server information about the first network interface card’s configuration, including IP address, gateways, subnet mask, DHCP information, and whether WINS is available.

T1021.001
Remote Desktop Protocol
GroupLazarus Group

Lazarus Group malware SierraCharlie uses RDP for propagation.

T1021.002
SMB/Windows Admin Shares
GroupLazarus Group

Lazarus Group malware SierraAlfa accesses the ADMIN$ share via SMB to conduct lateral movement.

T1027.013
Encrypted/Encoded File
GroupLazarus Group

Lazarus Group has used multiple types of encryption and encoding for their payloads, including AES, Caracachs, RC4, XOR, Base64, and other tricks such as creating aliases in code for Native API function names.

T1033
System Owner/User Discovery
GroupLazarus Group

Various Lazarus Group malware enumerates logged-on users.

T1041
Exfiltration Over C2 Channel
GroupLazarus Group

Lazarus Group has exfiltrated data and files over a C2 channel through its various tools and malware.

T1047
Windows Management Instrumentation
GroupLazarus Group

Lazarus Group has used WMIC for discovery as well as to execute payloads for persistence and lateral movement.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
GroupLazarus Group

Lazarus Group malware SierraBravo-Two generates an email message via SMTP containing information about newly infected victims.

T1056.001
Keylogging
GroupLazarus Group

Lazarus Group malware KiloAlfa contains keylogging functionality.

T1057
Process Discovery
GroupLazarus Group

Several Lazarus Group malware families gather a list of running processes on a victim system and send it to their C2 server. A Destover-like variant used by Lazarus Group also gathers process times.

T1059.003
Windows Command Shell
GroupLazarus Group

Lazarus Group malware uses cmd.exe to execute commands on a compromised host. A Destover-like variant used by Lazarus Group uses a batch file mechanism to delete its binaries from the system.

T1070.004
File Deletion
GroupLazarus Group

Lazarus Group malware has deleted files in various ways, including "suicide scripts" to delete malware binaries from the victim. Lazarus Group also uses secure file deletion to delete files from the victim.

T1070.006
Timestomp
GroupLazarus Group

Several Lazarus Group malware families use timestomping, including modifying the last write timestamp of a specified Registry key to a random date, as well as copying the timestamp for legitimate .exe files (such as calc.exe or mspaint.exe) to its dropped files.

T1074.001
Local Data Staging
GroupLazarus Group

Lazarus Group malware IndiaIndia saves information gathered about the victim to a file that is saved in the %TEMP% directory, then compressed, encrypted, and uploaded to a C2 server.

T1082
System Information Discovery
GroupLazarus Group

Several Lazarus Group malware families collect information on the type and version of the victim OS, as well as the victim computer name and CPU information.

T1083
File and Directory Discovery
GroupLazarus Group

Lazarus Group malware can use a common function to identify target files by their extension, and some also enumerate files and directories, including a Destover-like variant that lists files and gathers information for all drives.

T1098
Account Manipulation
GroupLazarus Group

Lazarus Group malware WhiskeyDelta-Two contains a function that attempts to rename the administrator’s account.

T1105
Ingress Tool Transfer
GroupLazarus Group

Lazarus Group has downloaded files, malware, and tools from its C2 onto a compromised host.

T1110.003
Password Spraying
GroupLazarus Group

Lazarus Group malware attempts to connect to Windows shares for lateral movement by using a generated list of usernames, which center around permutations of the username Administrator, and weak passwords.

T1134.002
Create Process with Token
GroupLazarus Group

Lazarus Group keylogger KiloAlfa obtains user tokens from interactive sessions to execute itself with API call CreateProcessAsUserA under that user's context.

T1485
Data Destruction
GroupLazarus Group

Lazarus Group has used a custom secure delete function to overwrite file contents with data from heap memory.

T1542.003
Bootkit
GroupLazarus Group

Lazarus Group malware WhiskeyAlfa-Three modifies sector 0 of the Master Boot Record (MBR) to ensure that the malware will persist even if a victim machine shuts down.

T1543.003
Windows Service
GroupLazarus Group

Several Lazarus Group malware families install themselves as new services.

T1547.001
Registry Run Keys / Startup Folder
GroupLazarus Group

Lazarus Group has maintained persistence by loading malicious code into a startup folder or by adding a Registry Run key.

T1560.003
Archive via Custom Method
GroupLazarus Group

A Lazarus Group malware sample encrypts data using a simple byte based XOR operation prior to exfiltration.

T1561.002
Disk Structure Wipe
GroupLazarus Group

Lazarus Group malware SHARPKNOT overwrites and deletes the Master Boot Record (MBR) on the victim's machine and has possessed MBR wiper malware since at least 2009.

T1571
Non-Standard Port
GroupLazarus Group

Some Lazarus Group malware uses a list of ordered port numbers to choose a port for C2 traffic, creating port-protocol mismatches.

T1573.001
Symmetric Cryptography
GroupLazarus Group

Several Lazarus Group malware families encrypt C2 traffic using custom code that uses XOR with an ADD operation and XOR with a SUB operation. Another Lazarus Group malware sample XORs C2 traffic. Other Lazarus Group malware uses Caracachs encryption to encrypt C2 payloads. Lazarus Group has also used AES to encrypt C2 traffic.

T1680
Local Storage Discovery
GroupLazarus Group

A Destover-like variant used by Lazarus Group collects disk space information and sends it to its C2 server.

T1685
Disable or Modify Tools
GroupLazarus Group

Lazarus Group malware TangoDelta attempts to terminate various processes associated with McAfee. Additionally, Lazarus Group malware SHARPKNOT disables the Microsoft Windows System Event Notification and Alerter services..

T1686.003
Windows Host Firewall
GroupLazarus Group

Various Lazarus Group malware modifies the Windows firewall to allow incoming connections or disable it entirely using netsh.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.