ATT&CKReferencesMandiant APT1

Mandiant APT1

Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

Open the source

Techniques7

Groups1

Software8

Campaigns0

None recorded.

Procedure examples33

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupAPT1

APT1 has been known to use credential dumping using Mimikatz.

T1003.001
LSASS Memory
ToolLslsass

Lslsass can dump active logon session password hashes from the lsass process.

T1003.002
Security Account Manager
ToolFgdump

Fgdump can dump Windows password hashes.

T1003.005
Cached Domain Credentials
ToolCachedump

Cachedump can extract cached password hashes from cache entry information.

T1005
Data from Local System
GroupAPT1

APT1 has collected files from a local victim.

T1007
System Service Discovery
GroupAPT1

APT1 used the commands net start and tasklist to get a listing of the services on the system.

T1008
Fallback Channels
MalwareBISCUIT

BISCUIT malware contains a secondary fallback command and control server that is contacted after the primary command and control server.

T1016
System Network Configuration Discovery
GroupAPT1

APT1 used the ipconfig /all command to gather network configuration information.

T1036.005
Match Legitimate Resource Name or Location
GroupAPT1

The file name AcroRD32.exe, a legitimate process name for Adobe's Acrobat Reader, was used by APT1 as a name for malware.

T1049
System Network Connections Discovery
GroupAPT1

APT1 used the net use command to get a listing on network connections.

T1057
Process Discovery
GroupAPT1

APT1 gathered a list of running processes on the system using tasklist /v.

T1059.003
Windows Command Shell
MalwareWEBC2

WEBC2 can open an interactive command shell.

T1059.003
Windows Command Shell
GroupAPT1

APT1 has used the Windows command shell to execute commands, and batch scripting to automate execution.

T1082
System Information Discovery
MalwareBISCUIT

BISCUIT has a command to collect the processor type, operation system, computer name, and whether the system is a laptop or PC.

T1087.001
Local Account
GroupAPT1

APT1 used the commands net localgroup,net user, and net group to find accounts on the system.

T1102.002
Bidirectional Communication
MalwareGLOOXMAIL

GLOOXMAIL communicates to servers operated by Google using the Jabber/XMPP protocol.

T1102.002
Bidirectional Communication
MalwareCALENDAR

The CALENDAR malware communicates through the use of events in Google Calendar.

T1105
Ingress Tool Transfer
MalwareWEBC2

WEBC2 can download and execute a file.

T1114.001
Local Email Collection
GroupAPT1

APT1 uses two utilities, GETMAIL and MAPIGET, to steal email. GETMAIL extracts emails from archived Outlook .pst files.

T1114.002
Remote Email Collection
GroupAPT1

APT1 uses two utilities, GETMAIL and MAPIGET, to steal email. MAPIGET steals email still on Exchange servers that has not yet been archived.

T1119
Automated Collection
GroupAPT1

APT1 used a batch script to perform a series of discovery techniques and saves it to a text file.

T1124
System Time Discovery
MalwareBISCUIT

BISCUIT has a command to collect the system `UPTIME`.

T1135
Network Share Discovery
GroupAPT1

APT1 listed connected network shares.

T1550.002
Pass the Hash
GroupAPT1

The APT1 group is known to have used pass the hash.

T1550.002
Pass the Hash
ToolPass-The-Hash Toolkit

Pass-The-Hash Toolkit can perform pass the hash.

T1560.001
Archive via Utility
GroupAPT1

APT1 has used RAR to compress files before moving them outside of the victim network.

T1566.001
Spearphishing Attachment
GroupAPT1

APT1 has sent spearphishing emails containing malicious attachments.

T1566.002
Spearphishing Link
GroupAPT1

APT1 has sent spearphishing emails containing hyperlinks to malicious files.

T1583.001
Domains
GroupAPT1

APT1 has registered hundreds of domains for use in operations.

T1584.001
Domains
GroupAPT1

APT1 hijacked FQDNs associated with legitimate websites hosted by hop points.

T1585.002
Email Accounts
GroupAPT1

APT1 has created email accounts for later use in social engineering, phishing, and when registering domains.

T1588.001
Malware
GroupAPT1

APT1 used publicly available malware for privilege escalation.

T1588.002
Tool
GroupAPT1

APT1 has used various open-source tools for privilege escalation purposes.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.