ATT&CKReferencesCheck Point APT35 CharmPower January 2022

Check Point APT35 CharmPower January 2022

Check Point. (2022, January 11). APT35 exploits Log4j vulnerability to distribute new modular PowerShell toolkit. Retrieved January 24, 2022.

Open the source

Techniques1

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples29

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareCharmPower

CharmPower can collect data and files from a compromised host.

T1008
Fallback Channels
MalwareCharmPower

CharmPower can change its C2 channel once every 360 loops by retrieving a new domain from the actors’ S3 bucket.

T1012
Query Registry
MalwareCharmPower

CharmPower has the ability to enumerate `Uninstall` registry values.

T1016
System Network Configuration Discovery
MalwareCharmPower

CharmPower has the ability to use ipconfig to enumerate system network settings.

T1016.002
Wi-Fi Discovery
GroupMagic Hound

Magic Hound has collected names and passwords of all Wi-Fi networks to which a device has previously connected.

T1016.002
Wi-Fi Discovery
MalwareCharmPower

CharmPower can use `netsh wlan show profiles` to list specific Wi-Fi profile details.

T1041
Exfiltration Over C2 Channel
MalwareCharmPower

CharmPower can exfiltrate gathered data to a hardcoded C2 URL via HTTP POST.

T1047
Windows Management Instrumentation
MalwareCharmPower

CharmPower can use `wmic` to gather information from a system.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwareCharmPower

CharmPower can send victim data via FTP with credentials hardcoded in the script.

T1057
Process Discovery
MalwareCharmPower

CharmPower has the ability to list running processes through the use of `tasklist`.

T1059.001
PowerShell
MalwareCharmPower

CharmPower can use PowerShell for payload execution and C2 communication.

T1059.003
Windows Command Shell
MalwareCharmPower

The C# implementation of the CharmPower command execution module can use cmd.

T1070.004
File Deletion
MalwareCharmPower

CharmPower can delete created files from a compromised system.

T1071.001
Web Protocols
MalwareCharmPower

CharmPower can use HTTP to communicate with C2.

T1082
System Information Discovery
MalwareCharmPower

CharmPower can enumerate the OS version and computer name on a targeted system.

T1083
File and Directory Discovery
MalwareCharmPower

CharmPower can enumerate drives and list the contents of the C: drive on a victim's computer.

T1102
Web Service
MalwareCharmPower

CharmPower can download additional modules from actor-controlled Amazon S3 buckets.

T1102.001
Dead Drop Resolver
MalwareCharmPower

CharmPower can retrieve C2 domain information from actor-controlled S3 buckets.

T1105
Ingress Tool Transfer
MalwareCharmPower

CharmPower has the ability to download additional modules to a compromised host.

T1112
Modify Registry
MalwareCharmPower

CharmPower can remove persistence-related artifacts from the Registry.

T1113
Screen Capture
MalwareCharmPower

CharmPower has the ability to capture screenshots.

T1132.001
Standard Encoding
MalwareCharmPower

CharmPower can send additional modules over C2 encoded with base64.

T1140
Deobfuscate/Decode Files or Information
MalwareCharmPower

CharmPower can decrypt downloaded modules prior to execution.

T1190
Exploit Public-Facing Application
GroupMagic Hound

Magic Hound has exploited the Log4j utility (CVE-2021-44228), on-premises MS Exchange servers via "ProxyShell" (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207), and Fortios SSL VPNs (CVE-2018-13379).

T1518
Software Discovery
MalwareCharmPower

CharmPower can list the installed applications on a compromised host.

T1573.001
Symmetric Cryptography
MalwareCharmPower

CharmPower can send additional modules over C2 encrypted with a simple substitution cipher.

T1583.006
Web Services
GroupMagic Hound

Magic Hound has acquired Amazon S3 buckets to use in C2.

T1588.002
Tool
GroupMagic Hound

Magic Hound has obtained and used tools like Havij, sqlmap, Metasploit, Mimikatz, and Plink.

T1595.002
Vulnerability Scanning
GroupMagic Hound

Magic Hound has conducted widespread scanning to identify public-facing systems vulnerable to CVE-2021-44228 in Log4j and ProxyShell vulnerabilities; CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065 in on-premises MS Exchange Servers; and CVE-2018-13379 in Fortinet FortiOS SSL VPNs.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.