ATT&CKReferencesMandiant APT29 Eye Spy Email Nov 22

Mandiant APT29 Eye Spy Email Nov 22

Mandiant. (2022, May 2). UNC3524: Eye Spy on Your Email. Retrieved August 17, 2023.

Open the source

Techniques2

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples23

TechniqueUsed byProcedure example
T1003.002
Security Account Manager
GroupAPT29

APT29 has used the `reg save` command to save registry hives.

T1003.004
LSA Secrets
GroupAPT29

APT29 has used the `reg save` command to extract LSA secrets offline.

T1005
Data from Local System
GroupAPT29

APT29 has stolen data from compromised hosts.

T1008
Fallback Channels
MalwareQUIETEXIT

QUIETEXIT can attempt to connect to a second hard-coded C2 if the first hard-coded C2 address fails.

T1016.001
Internet Connection Discovery
GroupAPT29

APT29 has ensured web servers in a victim environment are Internet accessible before copying tools or malware to it.

T1036.005
Match Legitimate Resource Name or Location
MalwareQUIETEXIT

QUIETEXIT has attempted to change its name to `cron` upon startup. During incident response, QUIETEXIT samples have been identified that were renamed to blend in with other legitimate files.

T1037
Boot or Logon Initialization Scripts
GroupAPT29

APT29 has hijacked legitimate application-specific startup scripts to enable malware to execute on system startup.

T1037.004
RC Scripts
GroupAPT29

APT29 has installed a run command on a compromised system to enable malware execution on system startup.

T1070.006
Timestomp
GroupAPT29

APT29 has used timestomping to alter the Standard Information timestamps on their web shells to match other files in the same directory.

T1071
Application Layer Protocol
MalwareQUIETEXIT

QUIETEXIT can use an inverse negotiated SSH connection as part of its C2.

T1078.004
Cloud Accounts
GroupAPT29

APT29 has gained access to a global administrator account in Azure AD and has used `Service Principal` credentials in Exchange.

T1090
Proxy
MalwarereGeorg

reGeorg can establish an HTTP or SOCKS proxy to tunnel data in and out of a network.

T1090.002
External Proxy
MalwareQUIETEXIT

QUIETEXIT can proxy traffic via SOCKS.

T1095
Non-Application Layer Protocol
MalwareQUIETEXIT

QUIETEXIT can establish a TCP connection as part of its initial connection to the C2.

T1098.002
Additional Email Delegate Permissions
GroupAPT29

APT29 has used a compromised global administrator account in Azure AD to backdoor a service principal with `ApplicationImpersonation` rights to start collecting emails from targeted mailboxes; APT29 has also used compromised accounts holding `ApplicationImpersonation` rights in Exchange to collect emails.

T1105
Ingress Tool Transfer
GroupAPT29

APT29 has downloaded additional tools and malware onto compromised networks.

T1114.002
Remote Email Collection
GroupAPT29

APT29 has collected emails from targeted mailboxes within a compromised Azure AD tenant and compromised Exchange servers, including via Exchange Web Services (EWS) API requests.

T1505.003
Web Shell
GroupAPT29

APT29 has installed web shells on exploited Microsoft Exchange servers.

T1505.003
Web Shell
MalwarereGeorg

reGeorg is a web shell that has been installed on exposed web servers for access to victim environments.

T1568
Dynamic Resolution
GroupAPT29

APT29 has used Dynamic DNS providers for their malware C2 infrastructure.

T1572
Protocol Tunneling
MalwarereGeorg

reGeorg can tunnel TCP sessions including RDP, SSH, and SMB through HTTP.

T1587.001
Malware
GroupAPT29

APT29 has used unique malware in many of their operations.

T1588.002
Tool
GroupAPT29

APT29 has obtained and used a variety of tools including Mimikatz, SDelete, Tor, meek, and Cobalt Strike.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.