Dahan, A. (2017). Operation Cobalt Kitty. Retrieved December 27, 2018.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003 OS Credential Dumping |
GroupAPT32 | APT32 used GetPassword_x64 to harvest credentials. |
| T1003.001 LSASS Memory |
GroupAPT32 | APT32 used Mimikatz and customized versions of Windows Credential Dumper to harvest credentials. |
| T1005 Data from Local System |
MalwareGoopy | Goopy has the ability to exfiltrate documents from infected systems. |
| T1012 Query Registry |
MalwareDenis | Denis queries the Registry for keys and values. |
| T1016 System Network Configuration Discovery |
MalwareDenis | Denis uses |
| T1016 System Network Configuration Discovery |
GroupAPT32 | APT32 used the |
| T1018 Remote System Discovery |
GroupAPT32 | APT32 has enumerated DC servers using the command |
| T1021.002 SMB/Windows Admin Shares |
GroupAPT32 | APT32 used Net to use Windows' hidden network shares to copy their tools to remote machines for execution. |
| T1027 Obfuscated Files or Information |
MalwareDenis | Denis obfuscates its code and encrypts the API names. |
| T1027.001 Binary Padding |
MalwareGoopy | Goopy has had null characters padded in its malicious DLL payload. |
| T1027.010 Command Obfuscation |
MalwareDenis | Denis has encoded its PowerShell commands in Base64. |
| T1027.010 Command Obfuscation |
GroupAPT32 | APT32 has used the `Invoke-Obfuscation` framework to obfuscate their PowerShell. |
| T1027.013 Encrypted/Encoded File |
GroupAPT32 | APT32 has performed code obfuscation, including encoding payloads using Base64 and using a framework called "Dont-Kill-My-Cat (DKMC). APT32 also encrypts the library used for network exfiltration with AES-256 in CBC mode in their macOS backdoor. |
| T1027.016 Junk Code Insertion |
MalwareGoopy | Goopy's decrypter have been inflated with junk code in between legitimate API functions, and also included infinite loops to avoid analysis. |
| T1033 System Owner/User Discovery |
MalwareDenis | Denis enumerates and collects the username from the victim’s machine. |
| T1033 System Owner/User Discovery |
GroupAPT32 | APT32 collected the victim's username and executed the |
| T1033 System Owner/User Discovery |
MalwareGoopy | Goopy has the ability to enumerate the infected system's user name. |
| T1036 Masquerading |
GroupAPT32 | APT32 has disguised a Cobalt Strike beacon as a Flash Installer. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareGoopy | Goopy has impersonated the legitimate goopdate.dll, which was dropped on the target system with a legitimate GoogleUpdate.exe. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupAPT32 | APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update. APT32 has also renamed a Cobalt Strike beacon payload to install_flashplayers.exe. |
| T1041 Exfiltration Over C2 Channel |
MalwareGoopy | Goopy has the ability to exfiltrate data over the Microsoft Outlook C2 channel. |
| T1046 Network Service Discovery |
GroupAPT32 | APT32 performed network scanning on the network to search for open ports, services, OS finger-printing, and other vulnerabilities. |
| T1047 Windows Management Instrumentation |
GroupAPT32 | APT32 used WMI to deploy their tools on remote machines and to gather information about the Outlook process. |
| T1049 System Network Connections Discovery |
GroupAPT32 | APT32 used the |
| T1053.005 Scheduled Task |
MalwareGoopy | Goopy has the ability to maintain persistence by creating scheduled tasks set to run every hour. |
| T1053.005 Scheduled Task |
GroupAPT32 | APT32 has used scheduled tasks to persist on victim systems. |
| T1055 Process Injection |
GroupAPT32 | APT32 malware has injected a Cobalt Strike beacon into Rundll32.exe. |
| T1055.012 Process Hollowing |
MalwareDenis | Denis performed process hollowing through the API calls CreateRemoteThread, ResumeThread, and Wow64SetThreadContext. |
| T1056.001 Keylogging |
GroupAPT32 | APT32 has abused the PasswordChangeNotify to monitor for and capture account password changes. |
| T1057 Process Discovery |
MalwareGoopy | Goopy has checked for the Google Updater process to ensure Goopy was loaded properly. |
| T1059 Command and Scripting Interpreter |
GroupAPT32 | APT32 has used COM scriptlets to download Cobalt Strike beacons. |
| T1059.001 PowerShell |
MalwareDenis | Denis has a version written in PowerShell. |
| T1059.001 PowerShell |
GroupAPT32 | APT32 has used PowerShell-based tools, PowerShell one-liners, and shellcode loaders for execution. |
| T1059.003 Windows Command Shell |
MalwareDenis | Denis can launch a remote shell to execute arbitrary commands on the victim’s machine. |
| T1059.003 Windows Command Shell |
GroupAPT32 | APT32 has used cmd.exe for execution. |
| T1059.003 Windows Command Shell |
MalwareGoopy | Goopy has the ability to use cmd.exe to execute commands passed from an Outlook C2 channel. |
| T1059.005 Visual Basic |
GroupAPT32 | APT32 has used macros, COM scriptlets, and VBS scripts. |
| T1059.005 Visual Basic |
MalwareGoopy | Goopy has the ability to use a Microsoft Outlook backdoor macro to communicate with its C2. |
| T1059.007 JavaScript |
GroupAPT32 | APT32 has used JavaScript for drive-by downloads and C2 communications. |
| T1070.004 File Deletion |
MalwareDenis | Denis has a command to delete files from the victim’s machine. |
| T1070.008 Clear Mailbox Data |
MalwareGoopy | Goopy has the ability to delete emails used for C2 once the content has been copied. |
| T1071.001 Web Protocols |
GroupAPT32 | APT32 has used JavaScript that communicates over HTTP or HTTPS to attacker controlled domains to download additional frameworks. The group has also used downloaded encrypted payloads over HTTP. |
| T1071.001 Web Protocols |
MalwareGoopy | Goopy has the ability to communicate with its C2 over HTTP. |
| T1071.003 Mail Protocols |
GroupAPT32 | APT32 has used email for C2 via an Office macro. |
| T1071.003 Mail Protocols |
MalwareGoopy | Goopy has the ability to use a Microsoft Outlook backdoor macro to communicate with its C2. |
| T1071.004 DNS |
MalwareDenis | Denis has used DNS tunneling for C2 communications. |
| T1071.004 DNS |
MalwareGoopy | Goopy has the ability to communicate with its C2 over DNS. |
| T1082 System Information Discovery |
MalwareDenis | Denis collects OS information and the computer name from the victim’s machine. |
| T1083 File and Directory Discovery |
MalwareDenis | Denis has several commands to search directories for files. |
| T1087.001 Local Account |
GroupAPT32 | APT32 enumerated administrative users using the commands |
Showing the first 50.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.