ATT&CKReferencesUnit 42 Sofacy Feb 2018

Unit 42 Sofacy Feb 2018

Lee, B, et al. (2018, February 28). Sofacy Attacks Multiple Government Entities. Retrieved March 15, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples10

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
GroupAPT28

APT28 encrypted a .dll payload using RTL and a custom encryption algorithm. APT28 has also obfuscated payloads with base64, XOR, and RC4.

T1055
Process Injection
MalwareJHUHUGIT

JHUHUGIT performs code injection injecting its own functions to browser processes.

T1057
Process Discovery
MalwareJHUHUGIT

JHUHUGIT obtains a list of running processes on the victim.

T1070.004
File Deletion
MalwareJHUHUGIT

The JHUHUGIT dropper can delete itself from the victim. Another JHUHUGIT variant has the capability to delete specified files.

T1071.001
Web Protocols
MalwareJHUHUGIT

JHUHUGIT variants have communicated with C2 servers over HTTP and HTTPS.

T1105
Ingress Tool Transfer
MalwareJHUHUGIT

JHUHUGIT can retrieve an additional payload from its C2 server. JHUHUGIT has a command to download files to the victim’s machine.

T1140
Deobfuscate/Decode Files or Information
GroupAPT28

An APT28 macro uses the command certutil -decode to decode contents of a .txt file storing the base64 encoded payload.

T1204.002
Malicious File
GroupAPT28

APT28 attempted to get users to click on Microsoft Office attachments containing malicious macro scripts.

T1566.001
Spearphishing Attachment
GroupAPT28

APT28 sent spearphishing emails containing malicious Microsoft Office and RAR attachments.

T1680
Local Storage Discovery
MalwareJHUHUGIT

JHUHUGIT obtains a build identifier as well as victim hard drive information from Windows registry key HKLM\SYSTEM\CurrentControlSet\Services\Disk\Enum. Another JHUHUGIT variant gathers the victim storage volume serial number and the storage device name.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.