ATT&CKReferencesORB Mandiant

ORB Mandiant

Raggi, Michael. (2024, May 22). IOC Extinction? China-Nexus Cyber Espionage Actors Use ORB Networks to Raise Cost on Defenders. Retrieved July 8, 2024.

Open the source

Techniques2

Groups0

None recorded.

Software0

None recorded.

Campaigns2

Procedure examples15

TechniqueUsed byProcedure example
T1059
Command and Scripting Interpreter
CampaignFLORAHOX Activity

FLORAHOX Activity has executed PHP and Shell scripts to identify and infect subsequent routers for the ORB network.

T1059.004
Unix Shell
CampaignFLORAHOX Activity

FLORAHOX Activity has executed multiple Bash controller scripts to provide command line inputs for FLORAHOX traversal configurations.

T1090.003
Multi-hop Proxy
GroupZIRCONIUM

ZIRCONIUM has utilized an ORB (operational relay box) network – consisting compromised devices such as small office and home office (SOHO) routers, IoT devices, and leased virtual private servers (VPS) – to proxy traffic.

T1090.003
Multi-hop Proxy
CampaignSPACEHOP Activity

SPACEHOP Activity has routed traffic through chains of compromised network devices to proxy C2 communications.

T1090.003
Multi-hop Proxy
CampaignFLORAHOX Activity

FLORAHOX Activity has routed traffic through a customized Tor relay network layer.

T1190
Exploit Public-Facing Application
CampaignFLORAHOX Activity

FLORAHOX Activity has exploited and infected vulnerable routers to recruit additional network devices into the ORB.

T1190
Exploit Public-Facing Application
CampaignSPACEHOP Activity

SPACEHOP Activity has enabled the exploitation of CVE-2022-27518 and CVE-2022-27518 for illegitimate access.

T1583.003
Virtual Private Server
CampaignSPACEHOP Activity

SPACEHOP Activity has used acquired Virtual Private Servers as control systems for devices within the ORB network.

T1583.003
Virtual Private Server
CampaignFLORAHOX Activity

FLORAHOX Activity has used acquired Virtual Private Servers as control systems for the ORB network.

T1583.005
Botnet
GroupKe3chang

Ke3chang has utilized an ORB (operational relay box) network for reconnaissance and vulnerability exploitation.

T1583.005
Botnet
GroupAPT5

APT5 has acquired a network of compromised systems – specifically an ORB (operational relay box) network – for follow on activities.

T1584.008
Network Devices
GroupZIRCONIUM

ZIRCONIUM has compromised network devices such as small office and home office (SOHO) routers and IoT devices for ORB (operational relay box) Proxy networks.

T1584.008
Network Devices
CampaignFLORAHOX Activity

FLORAHOX Activity has compromised network routers and IoT devices for the ORB network.

T1588.002
Tool
CampaignSPACEHOP Activity

SPACEHOP Activity leverages a C2 framework sourced from a publicly-available Github repository for administration of relay nodes.

T1665
Hide Infrastructure
GroupZIRCONIUM

ZIRCONIUM has utilized an ORB (operational relay box) network – consisting compromised devices such as small office and home office (SOHO) routers, IoT devices, and leased virtual private servers (VPS) – to obfuscate the origin of C2 traffic.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.