Kaspersky Lab's Global Research and Analysis Team. (2015, December 4). Sofacy APT hits high profile targets with updated toolset. Retrieved December 10, 2015.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1025 Data from Removable Media |
MalwareUSBStealer | Once a removable media device is inserted back into the first victim, USBStealer collects data from it that was exfiltrated from a second victim. |
| T1027 Obfuscated Files or Information |
MalwareADVSTORESHELL | Most of the strings in ADVSTORESHELL are encrypted with an XOR-based algorithm; some strings are also encrypted with 3DES and reversed. API function names are also reversed, presumably to avoid detection in memory. |
| T1071.001 Web Protocols |
MalwareADVSTORESHELL | ADVSTORESHELL connects to port 80 of a C2 server using Wininet API. Data is exchanged via HTTP POSTs. |
| T1074.001 Local Data Staging |
MalwareUSBStealer | USBStealer collects files matching certain criteria from the victim and stores them in a local directory for later exfiltration. |
| T1083 File and Directory Discovery |
MalwareUSBStealer | USBStealer searches victim drives for files matching certain extensions (“.skr”,“.pkr” or “.key”) or names. |
| T1132.001 Standard Encoding |
MalwareADVSTORESHELL | C2 traffic from ADVSTORESHELL is encrypted, then encoded with Base64 encoding. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareADVSTORESHELL | ADVSTORESHELL achieves persistence by adding itself to the |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.