ATT&CKReferencesBitdefender APT28 Dec 2015

Bitdefender APT28 Dec 2015

Bitdefender. (2015, December). APT28 Under the Scope. Retrieved February 23, 2017.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples18

TechniqueUsed byProcedure example
T1012
Query Registry
MalwareADVSTORESHELL

ADVSTORESHELL can enumerate registry keys.

T1027
Obfuscated Files or Information
MalwareADVSTORESHELL

Most of the strings in ADVSTORESHELL are encrypted with an XOR-based algorithm; some strings are also encrypted with 3DES and reversed. API function names are also reversed, presumably to avoid detection in memory.

T1027.013
Encrypted/Encoded File
GroupAPT28

APT28 encrypted a .dll payload using RTL and a custom encryption algorithm. APT28 has also obfuscated payloads with base64, XOR, and RC4.

T1056.001
Keylogging
MalwareADVSTORESHELL

ADVSTORESHELL can perform keylogging.

T1059.003
Windows Command Shell
MalwareADVSTORESHELL

ADVSTORESHELL can create a remote shell and run a given command.

T1068
Exploitation for Privilege Escalation
GroupAPT28

APT28 has exploited CVE-2014-4076, CVE-2015-2387, CVE-2015-1701, CVE-2017-0263, and CVE-2022-38028 to escalate privileges.

T1082
System Information Discovery
MalwareADVSTORESHELL

ADVSTORESHELL can run Systeminfo to gather information about the victim.

T1083
File and Directory Discovery
MalwareADVSTORESHELL

ADVSTORESHELL can list files and directories.

T1090.002
External Proxy
GroupAPT28

APT28 used other victims as proxies to relay command traffic, for instance using a compromised Georgian military email server as a hop point to NATO victims. The group has also used a tool that acts as a proxy to allow C2 even if the victim is behind a router. APT28 has also used a machine to relay and obscure communications between CHOPSTICK and their server.

T1105
Ingress Tool Transfer
GroupAPT28

APT28 has downloaded additional files, including by using a first-stage downloader to contact the C2 server to obtain the second-stage implant.

T1106
Native API
MalwareADVSTORESHELL

ADVSTORESHELL is capable of starting a process using CreateProcess.

T1112
Modify Registry
MalwareADVSTORESHELL

ADVSTORESHELL is capable of setting and deleting Registry values.

T1211
Exploitation for Stealth
GroupAPT28

APT28 has used CVE-2015-4902 to bypass security features.

T1218.011
Rundll32
GroupAPT28

APT28 executed CHOPSTICK by using rundll32 commands such as rundll32.exe “C:\Windows\twain_64.dll”. APT28 also executed a .dll for a first stage dropper using rundll32.exe. An APT28 loader Trojan saved a batch script that uses rundll32 to execute a DLL payload.

T1218.011
Rundll32
MalwareADVSTORESHELL

ADVSTORESHELL has used rundll32.exe in a Registry value to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareADVSTORESHELL

ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key.

T1573.001
Symmetric Cryptography
MalwareADVSTORESHELL

A variant of ADVSTORESHELL encrypts some C2 with 3DES.

T1573.002
Asymmetric Cryptography
MalwareADVSTORESHELL

A variant of ADVSTORESHELL encrypts some C2 with RSA.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.