Raggi, Michael. (2024, May 22). IOC Extinction? China-Nexus Cyber Espionage Actors Use ORB Networks to Raise Cost on Defenders. Retrieved July 8, 2024.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1059 Command and Scripting Interpreter |
CampaignFLORAHOX Activity | FLORAHOX Activity has executed PHP and Shell scripts to identify and infect subsequent routers for the ORB network. |
| T1059.004 Unix Shell |
CampaignFLORAHOX Activity | FLORAHOX Activity has executed multiple Bash controller scripts to provide command line inputs for FLORAHOX traversal configurations. |
| T1090.003 Multi-hop Proxy |
GroupZIRCONIUM | ZIRCONIUM has utilized an ORB (operational relay box) network – consisting compromised devices such as small office and home office (SOHO) routers, IoT devices, and leased virtual private servers (VPS) – to proxy traffic. |
| T1090.003 Multi-hop Proxy |
CampaignSPACEHOP Activity | SPACEHOP Activity has routed traffic through chains of compromised network devices to proxy C2 communications. |
| T1090.003 Multi-hop Proxy |
CampaignFLORAHOX Activity | FLORAHOX Activity has routed traffic through a customized Tor relay network layer. |
| T1190 Exploit Public-Facing Application |
CampaignFLORAHOX Activity | FLORAHOX Activity has exploited and infected vulnerable routers to recruit additional network devices into the ORB. |
| T1190 Exploit Public-Facing Application |
CampaignSPACEHOP Activity | SPACEHOP Activity has enabled the exploitation of CVE-2022-27518 and CVE-2022-27518 for illegitimate access. |
| T1583.003 Virtual Private Server |
CampaignSPACEHOP Activity | SPACEHOP Activity has used acquired Virtual Private Servers as control systems for devices within the ORB network. |
| T1583.003 Virtual Private Server |
CampaignFLORAHOX Activity | FLORAHOX Activity has used acquired Virtual Private Servers as control systems for the ORB network. |
| T1583.005 Botnet |
GroupKe3chang | Ke3chang has utilized an ORB (operational relay box) network for reconnaissance and vulnerability exploitation. |
| T1583.005 Botnet |
GroupAPT5 | APT5 has acquired a network of compromised systems – specifically an ORB (operational relay box) network – for follow on activities. |
| T1584.008 Network Devices |
GroupZIRCONIUM | ZIRCONIUM has compromised network devices such as small office and home office (SOHO) routers and IoT devices for ORB (operational relay box) Proxy networks. |
| T1584.008 Network Devices |
CampaignFLORAHOX Activity | FLORAHOX Activity has compromised network routers and IoT devices for the ORB network. |
| T1588.002 Tool |
CampaignSPACEHOP Activity | SPACEHOP Activity leverages a C2 framework sourced from a publicly-available Github repository for administration of relay nodes. |
| T1665 Hide Infrastructure |
GroupZIRCONIUM | ZIRCONIUM has utilized an ORB (operational relay box) network – consisting compromised devices such as small office and home office (SOHO) routers, IoT devices, and leased virtual private servers (VPS) – to obfuscate the origin of C2 traffic. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.