ATT&CKReferencesMcAfee Lazarus Resurfaces Feb 2018

McAfee Lazarus Resurfaces Feb 2018

Sherstobitoff, R. (2018, February 12). Lazarus Resurfaces, Targets Global Banks and Bitcoin Users. Retrieved February 19, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples19

TechniqueUsed byProcedure example
T1001.003
Protocol or Service Impersonation
GroupLazarus Group

Lazarus Group malware also uses a unique form of communication encryption known as FakeTLS that mimics TLS but uses a different encryption method, potentially evading SSL traffic inspection/decryption.

T1012
Query Registry
GroupLazarus Group

Lazarus Group malware IndiaIndia checks Registry keys within HKCU and HKLM to determine if certain applications are present, including SecureCRT, Terminal Services, RealVNC, TightVNC, UltraVNC, Radmin, mRemote, TeamViewer, FileZilla, pcAnyware, and Remote Desktop. Another Lazarus Group malware sample checks for the presence of the following Registry key:HKEY_CURRENT_USER\Software\Bitcoin\Bitcoin-Qt.

T1027.013
Encrypted/Encoded File
GroupLazarus Group

Lazarus Group has used multiple types of encryption and encoding for their payloads, including AES, Caracachs, RC4, XOR, Base64, and other tricks such as creating aliases in code for Native API function names.

T1033
System Owner/User Discovery
GroupLazarus Group

Various Lazarus Group malware enumerates logged-on users.

T1041
Exfiltration Over C2 Channel
GroupLazarus Group

Lazarus Group has exfiltrated data and files over a C2 channel through its various tools and malware.

T1055.001
Dynamic-link Library Injection
GroupLazarus Group

A Lazarus Group malware sample performs reflective DLL injection.

T1057
Process Discovery
GroupLazarus Group

Several Lazarus Group malware families gather a list of running processes on a victim system and send it to their C2 server. A Destover-like variant used by Lazarus Group also gathers process times.

T1059.003
Windows Command Shell
GroupLazarus Group

Lazarus Group malware uses cmd.exe to execute commands on a compromised host. A Destover-like variant used by Lazarus Group uses a batch file mechanism to delete its binaries from the system.

T1071.001
Web Protocols
GroupLazarus Group

Lazarus Group has conducted C2 over HTTP and HTTPS.

T1082
System Information Discovery
GroupLazarus Group

Several Lazarus Group malware families collect information on the type and version of the victim OS, as well as the victim computer name and CPU information.

T1132.001
Standard Encoding
GroupLazarus Group

A Lazarus Group malware sample encodes data with base64.

T1547.001
Registry Run Keys / Startup Folder
GroupLazarus Group

Lazarus Group has maintained persistence by loading malicious code into a startup folder or by adding a Registry Run key.

T1547.009
Shortcut Modification
GroupLazarus Group

Lazarus Group malware has maintained persistence on a system by creating a LNK shortcut in the user’s Startup folder.

T1560
Archive Collected Data
GroupLazarus Group

Lazarus Group has compressed exfiltrated data with RAR and used RomeoDelta malware to archive specified directories in .zip format, encrypt the .zip file, and upload it to C2.

T1560.002
Archive via Library
GroupLazarus Group

Lazarus Group malware IndiaIndia saves information gathered about the victim to a file that is compressed with Zlib, encrypted, and uploaded to a C2 server.

T1560.003
Archive via Custom Method
GroupLazarus Group

A Lazarus Group malware sample encrypts data using a simple byte based XOR operation prior to exfiltration.

T1564.001
Hidden Files and Directories
GroupLazarus Group

Lazarus Group has used a VBA Macro to set its file attributes to System and Hidden and has named files with a dot prefix to hide them from the Finder application.

T1573.001
Symmetric Cryptography
GroupLazarus Group

Several Lazarus Group malware families encrypt C2 traffic using custom code that uses XOR with an ADD operation and XOR with a SUB operation. Another Lazarus Group malware sample XORs C2 traffic. Other Lazarus Group malware uses Caracachs encryption to encrypt C2 payloads. Lazarus Group has also used AES to encrypt C2 traffic.

T1680
Local Storage Discovery
GroupLazarus Group

A Destover-like variant used by Lazarus Group collects disk space information and sends it to its C2 server.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.