Novetta Threat Research Group. (2016, February 24). Operation Blockbuster: Loaders, Installers and Uninstallers Report. Retrieved November 17, 2024.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
GroupLazarus Group | Lazarus Group has collected data and files from compromised networks. |
| T1010 Application Window Discovery |
GroupLazarus Group | Lazarus Group malware IndiaIndia obtains and sends to its C2 server the title of the window for each running process. The KilaAlfa keylogger also reports the title of the window in the foreground. |
| T1012 Query Registry |
GroupLazarus Group | Lazarus Group malware IndiaIndia checks Registry keys within HKCU and HKLM to determine if certain applications are present, including SecureCRT, Terminal Services, RealVNC, TightVNC, UltraVNC, Radmin, mRemote, TeamViewer, FileZilla, pcAnyware, and Remote Desktop. Another Lazarus Group malware sample checks for the presence of the following Registry key: |
| T1016 System Network Configuration Discovery |
GroupLazarus Group | Lazarus Group malware IndiaIndia obtains and sends to its C2 server information about the first network interface card’s configuration, including IP address, gateways, subnet mask, DHCP information, and whether WINS is available. |
| T1027.013 Encrypted/Encoded File |
GroupLazarus Group | Lazarus Group has used multiple types of encryption and encoding for their payloads, including AES, Caracachs, RC4, XOR, Base64, and other tricks such as creating aliases in code for Native API function names. |
| T1033 System Owner/User Discovery |
GroupLazarus Group | Various Lazarus Group malware enumerates logged-on users. |
| T1041 Exfiltration Over C2 Channel |
GroupLazarus Group | Lazarus Group has exfiltrated data and files over a C2 channel through its various tools and malware. |
| T1057 Process Discovery |
GroupLazarus Group | Several Lazarus Group malware families gather a list of running processes on a victim system and send it to their C2 server. A Destover-like variant used by Lazarus Group also gathers process times. |
| T1070.006 Timestomp |
GroupLazarus Group | Several Lazarus Group malware families use timestomping, including modifying the last write timestamp of a specified Registry key to a random date, as well as copying the timestamp for legitimate .exe files (such as calc.exe or mspaint.exe) to its dropped files. |
| T1074.001 Local Data Staging |
GroupLazarus Group | Lazarus Group malware IndiaIndia saves information gathered about the victim to a file that is saved in the %TEMP% directory, then compressed, encrypted, and uploaded to a C2 server. |
| T1082 System Information Discovery |
GroupLazarus Group | Several Lazarus Group malware families collect information on the type and version of the victim OS, as well as the victim computer name and CPU information. |
| T1105 Ingress Tool Transfer |
GroupLazarus Group | Lazarus Group has downloaded files, malware, and tools from its C2 onto a compromised host. |
| T1560 Archive Collected Data |
GroupLazarus Group | Lazarus Group has compressed exfiltrated data with RAR and used RomeoDelta malware to archive specified directories in .zip format, encrypt the .zip file, and upload it to C2. |
| T1560.003 Archive via Custom Method |
GroupLazarus Group | A Lazarus Group malware sample encrypts data using a simple byte based XOR operation prior to exfiltration. |
| T1680 Local Storage Discovery |
GroupLazarus Group | A Destover-like variant used by Lazarus Group collects disk space information and sends it to its C2 server. |
| T1685 Disable or Modify Tools |
GroupLazarus Group | Lazarus Group malware TangoDelta attempts to terminate various processes associated with McAfee. Additionally, Lazarus Group malware SHARPKNOT disables the Microsoft Windows System Event Notification and Alerter services.. |
| T1686.003 Windows Host Firewall |
GroupLazarus Group | Various Lazarus Group malware modifies the Windows firewall to allow incoming connections or disable it entirely using netsh. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.