Mandiant. (2022, May 2). UNC3524: Eye Spy on Your Email. Retrieved August 17, 2023.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.002 Security Account Manager |
GroupAPT29 | APT29 has used the `reg save` command to save registry hives. |
| T1003.004 LSA Secrets |
GroupAPT29 | APT29 has used the `reg save` command to extract LSA secrets offline. |
| T1005 Data from Local System |
GroupAPT29 | APT29 has stolen data from compromised hosts. |
| T1008 Fallback Channels |
MalwareQUIETEXIT | QUIETEXIT can attempt to connect to a second hard-coded C2 if the first hard-coded C2 address fails. |
| T1016.001 Internet Connection Discovery |
GroupAPT29 | APT29 has ensured web servers in a victim environment are Internet accessible before copying tools or malware to it. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareQUIETEXIT | QUIETEXIT has attempted to change its name to `cron` upon startup. During incident response, QUIETEXIT samples have been identified that were renamed to blend in with other legitimate files. |
| T1037 Boot or Logon Initialization Scripts |
GroupAPT29 | APT29 has hijacked legitimate application-specific startup scripts to enable malware to execute on system startup. |
| T1037.004 RC Scripts |
GroupAPT29 | APT29 has installed a run command on a compromised system to enable malware execution on system startup. |
| T1070.006 Timestomp |
GroupAPT29 | APT29 has used timestomping to alter the Standard Information timestamps on their web shells to match other files in the same directory. |
| T1071 Application Layer Protocol |
MalwareQUIETEXIT | QUIETEXIT can use an inverse negotiated SSH connection as part of its C2. |
| T1078.004 Cloud Accounts |
GroupAPT29 | APT29 has gained access to a global administrator account in Azure AD and has used `Service Principal` credentials in Exchange. |
| T1090 Proxy |
MalwarereGeorg | reGeorg can establish an HTTP or SOCKS proxy to tunnel data in and out of a network. |
| T1090.002 External Proxy |
MalwareQUIETEXIT | QUIETEXIT can proxy traffic via SOCKS. |
| T1095 Non-Application Layer Protocol |
MalwareQUIETEXIT | QUIETEXIT can establish a TCP connection as part of its initial connection to the C2. |
| T1098.002 Additional Email Delegate Permissions |
GroupAPT29 | APT29 has used a compromised global administrator account in Azure AD to backdoor a service principal with `ApplicationImpersonation` rights to start collecting emails from targeted mailboxes; APT29 has also used compromised accounts holding `ApplicationImpersonation` rights in Exchange to collect emails. |
| T1105 Ingress Tool Transfer |
GroupAPT29 | APT29 has downloaded additional tools and malware onto compromised networks. |
| T1114.002 Remote Email Collection |
GroupAPT29 | APT29 has collected emails from targeted mailboxes within a compromised Azure AD tenant and compromised Exchange servers, including via Exchange Web Services (EWS) API requests. |
| T1505.003 Web Shell |
GroupAPT29 | APT29 has installed web shells on exploited Microsoft Exchange servers. |
| T1505.003 Web Shell |
MalwarereGeorg | reGeorg is a web shell that has been installed on exposed web servers for access to victim environments. |
| T1568 Dynamic Resolution |
GroupAPT29 | APT29 has used Dynamic DNS providers for their malware C2 infrastructure. |
| T1572 Protocol Tunneling |
MalwarereGeorg | reGeorg can tunnel TCP sessions including RDP, SSH, and SMB through HTTP. |
| T1587.001 Malware |
GroupAPT29 | APT29 has used unique malware in many of their operations. |
| T1588.002 Tool |
GroupAPT29 | APT29 has obtained and used a variety of tools including Mimikatz, SDelete, Tor, meek, and Cobalt Strike. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.