ATT&CKReferencesCrowdStrike Grim Spider May 2019

CrowdStrike Grim Spider May 2019

John, E. and Carvey, H. (2019, May 30). Unraveling the Spiderweb: Timelining ATT&CK Artifacts Used by GRIM SPIDER. Retrieved May 12, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples16

TechniqueUsed byProcedure example
T1018
Remote System Discovery
GroupWizard Spider

Wizard Spider has used networkdll for network discovery and psfin specifically for financial and point of sale indicators. Wizard Spider has also used AdFind, nltest/dclist, and PowerShell script Get-DataInfo.ps1 to enumerate domain computers, including the domain controller.

T1021.001
Remote Desktop Protocol
GroupWizard Spider

Wizard Spider has used RDP for lateral movement and to deploy ransomware interactively.

T1036.004
Masquerade Task or Service
GroupWizard Spider

Wizard Spider has used scheduled tasks to install TrickBot, using task names to appear legitimate such as WinDotNet, GoogleTask, or Sysnetsf. It has also used common document file names for other malware binaries.

T1041
Exfiltration Over C2 Channel
GroupWizard Spider

Wizard Spider has exfiltrated domain credentials and network enumeration information over command and control (C2) channels.

T1047
Windows Management Instrumentation
GroupWizard Spider

Wizard Spider has used WMI and LDAP queries for network discovery and to move laterally. Wizard Spider has also used batch scripts to leverage WMIC to deploy ransomware.

T1053.005
Scheduled Task
GroupWizard Spider

Wizard Spider has used scheduled tasks to establish persistence for TrickBot and other malware.

T1059.001
PowerShell
GroupWizard Spider

Wizard Spider has used macros to execute PowerShell scripts to download malware on victim's machines. It has also used PowerShell to execute commands and move laterally through a victim network.

T1070.004
File Deletion
GroupWizard Spider

Wizard Spider has used file deletion to remove some modules and configurations from an infected host after use.

T1071.001
Web Protocols
GroupWizard Spider

Wizard Spider has used HTTP for network communications.

T1074
Data Staged
GroupWizard Spider

Wizard Spider has collected and staged credentials and network enumeration information, using the networkdll and psfin TrickBot modules.

T1078
Valid Accounts
GroupWizard Spider

Wizard Spider has used valid credentials for privileged accounts with the goal of accessing domain controllers.

T1112
Modify Registry
GroupWizard Spider

Wizard Spider has modified the Registry key HKLM\System\CurrentControlSet\Control\SecurityProviders\WDigest by setting the UseLogonCredential registry value to 1 in order to force credentials to be stored in clear text in memory. Wizard Spider has also modified the WDigest registry key to allow plaintext credentials to be cached in memory.

T1204.002
Malicious File
GroupWizard Spider

Wizard Spider has lured victims to execute malware with spearphishing attachments containing macros to download either Emotet, Bokbot, TrickBot, or Bazar.

T1543.003
Windows Service
GroupWizard Spider

Wizard Spider has installed TrickBot as a service named ControlServiceA in order to establish persistence.

T1566.001
Spearphishing Attachment
GroupWizard Spider

Wizard Spider has used spearphishing attachments to deliver Microsoft documents containing macros or PDFs containing malicious links to download either Emotet, Bokbot, TrickBot, or Bazar.

T1570
Lateral Tool Transfer
GroupWizard Spider

Wizard Spider has used stolen credentials to copy tools into the %TEMP% directory of domain controllers.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.