ATT&CKReferencesUnit 42 DarkHydrus July 2018

Unit 42 DarkHydrus July 2018

Falcone, R., et al. (2018, July 27). New Threat Actor Group DarkHydrus Targets Middle East Government. Retrieved August 2, 2018.

Open the source

Techniques1

Groups1

Software1

Campaigns0

None recorded.

Procedure examples20

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareRogueRobin

RogueRobin gathers the IP address and domain from the victim’s machine.

T1027.010
Command Obfuscation
MalwareRogueRobin

The PowerShell script with the RogueRobin payload was obfuscated using the COMPRESS technique in `Invoke-Obfuscation`.

T1033
System Owner/User Discovery
MalwareRogueRobin

RogueRobin collects the victim’s username and whether that user is an admin.

T1047
Windows Management Instrumentation
MalwareRogueRobin

RogueRobin uses various WMI queries to check if the sample is running in a sandbox.

T1057
Process Discovery
MalwareRogueRobin

RogueRobin checks the running processes for evidence it may be running in a sandbox environment. It specifically enumerates processes for Wireshark and Sysinternals.

T1059.001
PowerShell
GroupDarkHydrus

DarkHydrus leveraged PowerShell to download and execute additional scripts for execution.

T1059.001
PowerShell
MalwareRogueRobin

RogueRobin uses a command prompt to run a PowerShell script from Excel. To assist in establishing persistence, RogueRobin creates %APPDATA%\OneDrive.bat and saves the following string to it:powershell.exe -WindowStyle Hidden -exec bypass -File “%APPDATA%\OneDrive.ps1”.

T1059.003
Windows Command Shell
MalwareRogueRobin

RogueRobin uses Windows Script Components.

T1082
System Information Discovery
MalwareRogueRobin

RogueRobin gathers BIOS versions and manufacturers, the number of CPU cores, the total physical memory, and the computer name.

T1105
Ingress Tool Transfer
MalwareRogueRobin

RogueRobin can save a new file to the system from the C2 server.

T1113
Screen Capture
MalwareRogueRobin

RogueRobin has a command named $screenshot that may be responsible for taking screenshots of the victim machine.

T1132.001
Standard Encoding
MalwareRogueRobin

RogueRobin base64 encodes strings that are sent to the C2 over its DNS tunnel.

T1204.002
Malicious File
GroupDarkHydrus

DarkHydrus has sent malware that required users to hit the enable button in Microsoft Excel to allow an .iqy file to be downloaded.

T1497.001
System Checks
MalwareRogueRobin

RogueRobin uses WMI to check BIOS version for VBOX, bochs, qemu, virtualbox, and vm to check for evidence that the script might be executing within an analysis environment.

T1518.001
Security Software Discovery
MalwareRogueRobin

RogueRobin enumerates running processes to search for Wireshark and Windows Sysinternals suite.

T1547.001
Registry Run Keys / Startup Folder
MalwareRogueRobin

RogueRobin created a shortcut in the Windows startup folder to launch a PowerShell script each time the user logs in to establish persistence.

T1547.009
Shortcut Modification
MalwareRogueRobin

RogueRobin establishes persistence by creating a shortcut (.LNK file) in the Windows startup folder to run a script each time the user logs in.

T1564.003
Hidden Window
GroupDarkHydrus

DarkHydrus has used -WindowStyle Hidden to conceal PowerShell windows.

T1566.001
Spearphishing Attachment
GroupDarkHydrus

DarkHydrus has sent spearphishing emails with password-protected RAR archives containing malicious Excel Web Query files (.iqy). The group has also sent spearphishing emails that contained malicious Microsoft Office documents that use the “attachedTemplate” technique to load a template from a remote server.

T1588.002
Tool
GroupDarkHydrus

DarkHydrus has obtained and used tools such as Mimikatz, Empire, and Cobalt Strike.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.