ATT&CKReferencesMandiant APT1 Appendix

Mandiant APT1 Appendix

Mandiant. (n.d.). Appendix C (Digital) - The Malware Arsenal. Retrieved July 18, 2016.

Open the source

Techniques1

Groups0

None recorded.

Software2

Campaigns0

None recorded.

Procedure examples21

TechniqueUsed byProcedure example
T1008
Fallback Channels
MalwareBISCUIT

BISCUIT malware contains a secondary fallback command and control server that is contacted after the primary command and control server.

T1027.013
Encrypted/Encoded File
MalwareSeasalt

Seasalt obfuscates configuration data.

T1033
System Owner/User Discovery
MalwareBISCUIT

BISCUIT has a command to gather the username from the system.

T1036.004
Masquerade Task or Service
MalwareSeasalt

Seasalt has masqueraded as a service called "SaSaut" with a display name of "System Authorization Service" in an apparent attempt to masquerade as a legitimate service.

T1036.005
Match Legitimate Resource Name or Location
GroupAPT1

The file name AcroRD32.exe, a legitimate process name for Adobe's Acrobat Reader, was used by APT1 as a name for malware.

T1056.001
Keylogging
MalwareBISCUIT

BISCUIT can capture keystrokes.

T1057
Process Discovery
MalwareSeasalt

Seasalt has a command to perform a process listing.

T1057
Process Discovery
MalwareBISCUIT

BISCUIT has a command to enumerate running processes and identify their owners.

T1059.003
Windows Command Shell
MalwareBISCUIT

BISCUIT has a command to launch a command shell on the system.

T1059.003
Windows Command Shell
MalwareCALENDAR

CALENDAR has a command to run cmd.exe to execute commands.

T1059.003
Windows Command Shell
MalwareSeasalt

Seasalt uses cmd.exe to create a reverse shell on the infected endpoint.

T1070.004
File Deletion
MalwareSeasalt

Seasalt has a command to delete a specified file.

T1071.001
Web Protocols
MalwareSeasalt

Seasalt uses HTTP for C2 communications.

T1071.005
Publish/Subscribe Protocols
MalwareGLOOXMAIL

GLOOXMAIL communicates to servers operated by Google using the Jabber/XMPP protocol for C2.

T1102.002
Bidirectional Communication
MalwareCALENDAR

The CALENDAR malware communicates through the use of events in Google Calendar.

T1105
Ingress Tool Transfer
MalwareBISCUIT

BISCUIT has a command to download a file from the C2 server.

T1105
Ingress Tool Transfer
MalwareSeasalt

Seasalt has a command to download additional files.

T1113
Screen Capture
MalwareBISCUIT

BISCUIT has a command to periodically take screenshots of the system.

T1543.003
Windows Service
MalwareSeasalt

Seasalt is capable of installing itself as a service.

T1573.002
Asymmetric Cryptography
MalwareBISCUIT

BISCUIT uses SSL for encrypting C2 communications.

T1574.001
DLL
MalwareWEBC2

Variants of WEBC2 achieve persistence by using DLL search order hijacking, usually by copying the DLL file to %SYSTEMROOT% (C:\WINDOWS\ntshrui.dll).

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.