ATT&CKReferencesFireEye APT28

FireEye APT28

FireEye. (2015). APT28: A WINDOW INTO RUSSIA’S CYBER ESPIONAGE OPERATIONS?. Retrieved August 19, 2015.

Open the source

Techniques2

Groups1

Software3

Campaigns0

None recorded.

Procedure examples29

TechniqueUsed byProcedure example
T1001.001
Junk Data
GroupAPT28

APT28 added "junk data" to each encoded string, preventing trivial decoding without knowledge of the junk removal algorithm. Each implant was given a "junk length" value when created, tracked by the controller software to allow seamless communication but prevent analysis of the command protocol on the wire.

T1012
Query Registry
MalwareCHOPSTICK

CHOPSTICK provides access to the Windows Registry, which can be used to gather information.

T1027
Obfuscated Files or Information
MalwareCORESHELL

CORESHELL obfuscates strings using a custom stream cipher.

T1027
Obfuscated Files or Information
MalwareOLDBAIT

OLDBAIT obfuscates internal strings and unpacks them at startup.

T1027.011
Fileless Storage
MalwareCHOPSTICK

CHOPSTICK may store RC4 encrypted configuration information in the Windows Registry.

T1027.016
Junk Code Insertion
MalwareCORESHELL

CORESHELL contains unused machine instructions in a likely attempt to hinder analysis.

T1036.005
Match Legitimate Resource Name or Location
MalwareOLDBAIT

OLDBAIT installs itself in %ALLUSERPROFILE%\\Application Data\Microsoft\MediaPlayer\updatewindws.exe; the directory name is missing a space and the file name is missing the letter "o."

T1040
Network Sniffing
GroupAPT28

APT28 deployed the open source tool Responder to conduct NetBIOS Name Service poisoning, which captured usernames and hashed passwords that allowed access to legitimate credentials. APT28 close-access teams have used Wi-Fi pineapples to intercept Wi-Fi signals and user credentials.

T1071.001
Web Protocols
MalwareCORESHELL

CORESHELL can communicate over HTTP for C2.

T1071.001
Web Protocols
MalwareOLDBAIT

OLDBAIT can use HTTP for C2.

T1071.001
Web Protocols
GroupAPT28

Later implants used by APT28, such as CHOPSTICK, use a blend of HTTP, HTTPS, and other legitimate channels for C2, depending on module configuration.

T1071.003
Mail Protocols
MalwareCORESHELL

CORESHELL can communicate over SMTP and POP3 for C2.

T1071.003
Mail Protocols
GroupAPT28

APT28 has used IMAP, POP3, and SMTP for a communication channel in various implants, including using self-registered Google Mail accounts and later compromised email servers of its victims.

T1071.003
Mail Protocols
MalwareOLDBAIT

OLDBAIT can use SMTP for C2.

T1082
System Information Discovery
MalwareCORESHELL

CORESHELL collects hostname and OS version data from the victim and sends the information to its C2 server.

T1090.002
External Proxy
GroupAPT28

APT28 used other victims as proxies to relay command traffic, for instance using a compromised Georgian military email server as a hop point to NATO victims. The group has also used a tool that acts as a proxy to allow C2 even if the victim is behind a router. APT28 has also used a machine to relay and obscure communications between CHOPSTICK and their server.

T1091
Replication Through Removable Media
MalwareCHOPSTICK

Part of APT28's operation involved using CHOPSTICK modules to copy itself to air-gapped machines and using files written to USB sticks to transfer data and command traffic.

T1092
Communication Through Removable Media
MalwareCHOPSTICK

Part of APT28's operation involved using CHOPSTICK modules to copy itself to air-gapped machines, using files written to USB sticks to transfer data and command traffic.

T1105
Ingress Tool Transfer
MalwareCORESHELL

CORESHELL downloads another dropper from its C2 server.

T1112
Modify Registry
MalwareCHOPSTICK

CHOPSTICK may modify Registry keys to store RC4 encrypted configuration information.

T1132.001
Standard Encoding
MalwareCORESHELL

CORESHELL C2 messages are Base64-encoded.

T1210
Exploitation of Remote Services
GroupAPT28

APT28 exploited a Windows SMB Remote Code Execution Vulnerability to conduct lateral movement.

T1497
Virtualization/Sandbox Evasion
MalwareCHOPSTICK

CHOPSTICK includes runtime checks to identify an analysis environment and prevent execution on it.

T1518.001
Security Software Discovery
MalwareCHOPSTICK

CHOPSTICK checks for antivirus and forensics software.

T1555
Credentials from Password Stores
MalwareOLDBAIT

OLDBAIT collects credentials from several email clients.

T1555.003
Credentials from Web Browsers
MalwareOLDBAIT

OLDBAIT collects credentials from Internet Explorer, Mozilla Firefox, and Eudora.

T1573.001
Symmetric Cryptography
MalwareCORESHELL

CORESHELL C2 messages are encrypted with custom stream ciphers using six-byte or eight-byte keys.

T1583.001
Domains
GroupAPT28

APT28 registered domains imitating NATO, OSCE security websites, Caucasus information resources, and other organizations.

T1680
Local Storage Discovery
MalwareCORESHELL

CORESHELL collects the volume serial number from the victim and sends the information to its C2 server.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.