Falcone, R., et al. (2018, July 27). New Threat Actor Group DarkHydrus Targets Middle East Government. Retrieved August 2, 2018.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareRogueRobin | RogueRobin gathers the IP address and domain from the victim’s machine. |
| T1027.010 Command Obfuscation |
MalwareRogueRobin | The PowerShell script with the RogueRobin payload was obfuscated using the COMPRESS technique in `Invoke-Obfuscation`. |
| T1033 System Owner/User Discovery |
MalwareRogueRobin | RogueRobin collects the victim’s username and whether that user is an admin. |
| T1047 Windows Management Instrumentation |
MalwareRogueRobin | RogueRobin uses various WMI queries to check if the sample is running in a sandbox. |
| T1057 Process Discovery |
MalwareRogueRobin | RogueRobin checks the running processes for evidence it may be running in a sandbox environment. It specifically enumerates processes for Wireshark and Sysinternals. |
| T1059.001 PowerShell |
GroupDarkHydrus | DarkHydrus leveraged PowerShell to download and execute additional scripts for execution. |
| T1059.001 PowerShell |
MalwareRogueRobin | RogueRobin uses a command prompt to run a PowerShell script from Excel. To assist in establishing persistence, RogueRobin creates |
| T1059.003 Windows Command Shell |
MalwareRogueRobin | RogueRobin uses Windows Script Components. |
| T1082 System Information Discovery |
MalwareRogueRobin | RogueRobin gathers BIOS versions and manufacturers, the number of CPU cores, the total physical memory, and the computer name. |
| T1105 Ingress Tool Transfer |
MalwareRogueRobin | RogueRobin can save a new file to the system from the C2 server. |
| T1113 Screen Capture |
MalwareRogueRobin | RogueRobin has a command named |
| T1132.001 Standard Encoding |
MalwareRogueRobin | RogueRobin base64 encodes strings that are sent to the C2 over its DNS tunnel. |
| T1204.002 Malicious File |
GroupDarkHydrus | DarkHydrus has sent malware that required users to hit the enable button in Microsoft Excel to allow an .iqy file to be downloaded. |
| T1497.001 System Checks |
MalwareRogueRobin | RogueRobin uses WMI to check BIOS version for VBOX, bochs, qemu, virtualbox, and vm to check for evidence that the script might be executing within an analysis environment. |
| T1518.001 Security Software Discovery |
MalwareRogueRobin | RogueRobin enumerates running processes to search for Wireshark and Windows Sysinternals suite. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareRogueRobin | RogueRobin created a shortcut in the Windows startup folder to launch a PowerShell script each time the user logs in to establish persistence. |
| T1547.009 Shortcut Modification |
MalwareRogueRobin | RogueRobin establishes persistence by creating a shortcut (.LNK file) in the Windows startup folder to run a script each time the user logs in. |
| T1564.003 Hidden Window |
GroupDarkHydrus | DarkHydrus has used |
| T1566.001 Spearphishing Attachment |
GroupDarkHydrus | DarkHydrus has sent spearphishing emails with password-protected RAR archives containing malicious Excel Web Query files (.iqy). The group has also sent spearphishing emails that contained malicious Microsoft Office documents that use the “attachedTemplate” technique to load a template from a remote server. |
| T1588.002 Tool |
GroupDarkHydrus | DarkHydrus has obtained and used tools such as Mimikatz, Empire, and Cobalt Strike. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.