Accenture Security. (2018, November 29). SNAKEMACKEREL. Retrieved April 15, 2019.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.002 Software Packing |
MalwareZebrocy | Zebrocy's Delphi variant was packed with UPX. |
| T1027.013 Encrypted/Encoded File |
GroupAPT28 | APT28 encrypted a .dll payload using RTL and a custom encryption algorithm. APT28 has also obfuscated payloads with base64, XOR, and RC4. |
| T1041 Exfiltration Over C2 Channel |
MalwareZebrocy | Zebrocy has exfiltrated data to the designated C2 server using HTTP POST requests. |
| T1057 Process Discovery |
MalwareZebrocy | Zebrocy uses the |
| T1059.003 Windows Command Shell |
GroupAPT28 | An APT28 loader Trojan uses a cmd.exe and batch script to run its payload. The group has also used macros to execute payloads. |
| T1071.001 Web Protocols |
MalwareZebrocy | Zebrocy uses HTTP for C2. |
| T1082 System Information Discovery |
MalwareZebrocy | Zebrocy collects the OS version and computer name. Zebrocy also runs the |
| T1083 File and Directory Discovery |
MalwareZebrocy | Zebrocy searches for files that are 60mb and less and contain the following extensions: .doc, .docx, .xls, .xlsx, .ppt, .pptx, .exe, .zip, and .rar. Zebrocy also runs the |
| T1105 Ingress Tool Transfer |
MalwareZebrocy | Zebrocy obtains additional code to execute on the victim's machine, including the downloading of a secondary payload. |
| T1105 Ingress Tool Transfer |
GroupAPT28 | APT28 has downloaded additional files, including by using a first-stage downloader to contact the C2 server to obtain the second-stage implant. |
| T1113 Screen Capture |
MalwareZebrocy | A variant of Zebrocy captures screenshots of the victim’s machine in JPEG and BMP format. |
| T1132.001 Standard Encoding |
MalwareZebrocy | Zebrocy has used URL/Percent Encoding on data exfiltrated via HTTP POST requests. |
| T1204.002 Malicious File |
GroupAPT28 | APT28 attempted to get users to click on Microsoft Office attachments containing malicious macro scripts. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareZebrocy | Zebrocy creates an entry in a Registry Run key for the malware to execute on startup. |
| T1566.001 Spearphishing Attachment |
GroupAPT28 | APT28 sent spearphishing emails containing malicious Microsoft Office and RAR attachments. |
| T1680 Local Storage Discovery |
MalwareZebrocy | Zebrocy collects the serial number for the storage volume C:\. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.