ATT&CKReferencesMandiant No Easy Breach

Mandiant No Easy Breach

Dunwoody, M. and Carr, N.. (2016, September 27). No Easy Breach DerbyCon 2016. Retrieved September 12, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples18

TechniqueUsed byProcedure example
T1027.002
Software Packing
GroupAPT29

APT29 used UPX to pack files.

T1047
Windows Management Instrumentation
GroupAPT29

APT29 used WMI to steal credentials and execute backdoors at a future time.

T1053.005
Scheduled Task
GroupAPT29

APT29 has used named and hijacked scheduled tasks to establish persistence.

T1059.001
PowerShell
GroupAPT29

APT29 has used encoded PowerShell scripts uploaded to CozyCar installations to download and install SeaDuke.

T1070.004
File Deletion
GroupAPT29

APT29 has used SDelete to remove artifacts from victim networks.

T1090.003
Multi-hop Proxy
GroupAPT29

A backdoor used by APT29 created a Tor hidden service to forward traffic from the Tor client to local ports 3389 (RDP), 139 (Netbios), and 445 (SMB) enabling full remote access from outside the network and has also used TOR.

T1090.004
Domain Fronting
GroupAPT29

APT29 has used the meek domain fronting plugin for Tor to hide the destination of C2 traffic.

T1105
Ingress Tool Transfer
GroupAPT29

APT29 has downloaded additional tools and malware onto compromised networks.

T1546.003
Windows Management Instrumentation Event Subscription
GroupAPT29

APT29 has used WMI event subscriptions for persistence.

T1546.008
Accessibility Features
GroupAPT29

APT29 used sticky-keys to obtain unauthenticated, privileged console access.

T1547.001
Registry Run Keys / Startup Folder
GroupAPT29

APT29 added Registry Run keys to establish persistence.

T1548.002
Bypass User Account Control
GroupAPT29

APT29 has bypassed UAC.

T1550.003
Pass the Ticket
GroupAPT29

APT29 used Kerberos ticket attacks for lateral movement.

T1560.002
Archive via Library
MalwareSeaDuke

SeaDuke compressed data with zlib prior to sending it over C2.

T1566.002
Spearphishing Link
GroupAPT29

APT29 has used spearphishing with a link to trick victims into clicking on a link to a zip file containing malicious files.

T1573.001
Symmetric Cryptography
MalwareSeaDuke

SeaDuke C2 traffic has been encrypted with RC4 and AES.

T1587.001
Malware
GroupAPT29

APT29 has used unique malware in many of their operations.

T1588.002
Tool
GroupAPT29

APT29 has obtained and used a variety of tools including Mimikatz, SDelete, Tor, meek, and Cobalt Strike.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.