Bitdefender. (2015, December). APT28 Under the Scope. Retrieved February 23, 2017.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1012 Query Registry |
MalwareADVSTORESHELL | ADVSTORESHELL can enumerate registry keys. |
| T1027 Obfuscated Files or Information |
MalwareADVSTORESHELL | Most of the strings in ADVSTORESHELL are encrypted with an XOR-based algorithm; some strings are also encrypted with 3DES and reversed. API function names are also reversed, presumably to avoid detection in memory. |
| T1027.013 Encrypted/Encoded File |
GroupAPT28 | APT28 encrypted a .dll payload using RTL and a custom encryption algorithm. APT28 has also obfuscated payloads with base64, XOR, and RC4. |
| T1056.001 Keylogging |
MalwareADVSTORESHELL | ADVSTORESHELL can perform keylogging. |
| T1059.003 Windows Command Shell |
MalwareADVSTORESHELL | ADVSTORESHELL can create a remote shell and run a given command. |
| T1068 Exploitation for Privilege Escalation |
GroupAPT28 | APT28 has exploited CVE-2014-4076, CVE-2015-2387, CVE-2015-1701, CVE-2017-0263, and CVE-2022-38028 to escalate privileges. |
| T1082 System Information Discovery |
MalwareADVSTORESHELL | ADVSTORESHELL can run Systeminfo to gather information about the victim. |
| T1083 File and Directory Discovery |
MalwareADVSTORESHELL | ADVSTORESHELL can list files and directories. |
| T1090.002 External Proxy |
GroupAPT28 | APT28 used other victims as proxies to relay command traffic, for instance using a compromised Georgian military email server as a hop point to NATO victims. The group has also used a tool that acts as a proxy to allow C2 even if the victim is behind a router. APT28 has also used a machine to relay and obscure communications between CHOPSTICK and their server. |
| T1105 Ingress Tool Transfer |
GroupAPT28 | APT28 has downloaded additional files, including by using a first-stage downloader to contact the C2 server to obtain the second-stage implant. |
| T1106 Native API |
MalwareADVSTORESHELL | ADVSTORESHELL is capable of starting a process using CreateProcess. |
| T1112 Modify Registry |
MalwareADVSTORESHELL | ADVSTORESHELL is capable of setting and deleting Registry values. |
| T1211 Exploitation for Stealth |
GroupAPT28 | APT28 has used CVE-2015-4902 to bypass security features. |
| T1218.011 Rundll32 |
GroupAPT28 | APT28 executed CHOPSTICK by using rundll32 commands such as |
| T1218.011 Rundll32 |
MalwareADVSTORESHELL | ADVSTORESHELL has used rundll32.exe in a Registry value to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareADVSTORESHELL | ADVSTORESHELL achieves persistence by adding itself to the |
| T1573.001 Symmetric Cryptography |
MalwareADVSTORESHELL | A variant of ADVSTORESHELL encrypts some C2 with 3DES. |
| T1573.002 Asymmetric Cryptography |
MalwareADVSTORESHELL | A variant of ADVSTORESHELL encrypts some C2 with RSA. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.