ATT&CKReferencesBitDefender Chafer May 2020

BitDefender Chafer May 2020

Rusu, B. (2020, May 21). Iranian Chafer APT Targeted Air Transportation and Government in Kuwait and Saudi Arabia. Retrieved May 22, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples20

TechniqueUsed byProcedure example
T1003
OS Credential Dumping
GroupAPT39

APT39 has used different versions of Mimikatz to obtain credentials.

T1018
Remote System Discovery
GroupAPT39

APT39 has used NBTscan and custom tools to discover remote systems.

T1021.001
Remote Desktop Protocol
GroupAPT39

APT39 has been seen using RDP for lateral movement and persistence, in some cases employing the rdpwinst tool for mangement of multiple sessions.

T1027.002
Software Packing
GroupAPT39

APT39 has packed tools with UPX, and has repacked a modified version of Mimikatz to thwart anti-virus detection.

T1036.005
Match Legitimate Resource Name or Location
GroupAPT39

APT39 has used malware disguised as Mozilla Firefox and a tool named mfevtpse.exe to proxy C2 communications, closely mimicking a legitimate McAfee file mfevtps.exe.

T1046
Network Service Discovery
GroupAPT39

APT39 has used CrackMapExec and a custom port scanner known as BLUETORCH for network scanning.

T1053.005
Scheduled Task
GroupAPT39

APT39 has created scheduled tasks for persistence.

T1059.001
PowerShell
GroupAPT39

APT39 has used PowerShell to execute malicious code.

T1059.006
Python
GroupAPT39

APT39 has used a command line utility and a network scanner written in python.

T1071.001
Web Protocols
GroupAPT39

APT39 has used HTTP in communications with C2.

T1071.004
DNS
GroupAPT39

APT39 has used remote access tools that leverage DNS in communications with C2.

T1090.001
Internal Proxy
GroupAPT39

APT39 used custom tools to create SOCK5 and custom protocol proxies between infected hosts.

T1090.002
External Proxy
GroupAPT39

APT39 has used various tools to proxy C2 communications.

T1102.002
Bidirectional Communication
GroupAPT39

APT39 has communicated with C2 through files uploaded to and downloaded from DropBox.

T1135
Network Share Discovery
GroupAPT39

APT39 has used the post exploitation tool CrackMapExec to enumerate network shares.

T1136.001
Local Account
GroupAPT39

APT39 has created accounts on multiple compromised hosts to perform actions within the network.

T1204.002
Malicious File
GroupAPT39

APT39 has sent spearphishing emails in an attempt to lure users to click on a malicious attachment.

T1555
Credentials from Password Stores
GroupAPT39

APT39 has used the Smartftp Password Decryptor tool to decrypt FTP passwords.

T1569.002
Service Execution
GroupAPT39

APT39 has used post-exploitation tools including RemCom and the Non-sucking Service Manager (NSSM) to execute processes.

T1588.002
Tool
GroupAPT39

APT39 has modified and used customized versions of publicly-available tools like PLINK and Mimikatz.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.