ATT&CKReferencesDell TG-3390

Dell TG-3390

Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, August 5). Threat Group-3390 Targets Organizations for Cyberespionage. Retrieved August 18, 2018.

Open the source

Techniques2

Groups1

Software5

Campaigns0

None recorded.

Procedure examples37

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupThreat Group-3390

Threat Group-3390 actors have used a modified version of Mimikatz called Wrapikatz to dump credentials. They have also dumped credentials from domain controllers.

T1003.002
Security Account Manager
GroupThreat Group-3390

Threat Group-3390 actors have used gsecdump to dump credentials. They have also dumped credentials from domain controllers.

T1003.004
LSA Secrets
GroupThreat Group-3390

Threat Group-3390 actors have used gsecdump to dump credentials. They have also dumped credentials from domain controllers.

T1016
System Network Configuration Discovery
GroupThreat Group-3390

Threat Group-3390 actors use NBTscan to discover vulnerable systems.

T1027
Obfuscated Files or Information
MalwareHTTPBrowser

HTTPBrowser's code may be obfuscated through structured exception handling and return-oriented programming.

T1030
Data Transfer Size Limits
GroupThreat Group-3390

Threat Group-3390 actors have split RAR files for exfiltration into parts.

T1036.005
Match Legitimate Resource Name or Location
MalwareOwaAuth

OwaAuth uses the filename owaauth.dll, which is a legitimate file that normally resides in %ProgramFiles%\Microsoft\Exchange Server\ClientAccess\Owa\Auth\; the malicious file by the same name is saved in %ProgramFiles%\Microsoft\Exchange Server\ClientAccess\Owa\bin\.

T1046
Network Service Discovery
GroupThreat Group-3390

Threat Group-3390 actors use the Hunter tool to conduct network service discovery for vulnerable systems.

T1053.002
At
GroupThreat Group-3390

Threat Group-3390 actors use at to schedule tasks to run self-extracting RAR archives, which install HTTPBrowser or PlugX on other victims on a network.

T1056.001
Keylogging
GroupThreat Group-3390

Threat Group-3390 actors installed a credential logger on Microsoft Exchange servers. Threat Group-3390 also leveraged the reconnaissance framework, ScanBox, to capture keystrokes.

T1056.001
Keylogging
MalwareOwaAuth

OwaAuth captures and DES-encrypts credentials before writing the username and password to a log file, C:\log.txt.

T1056.001
Keylogging
MalwareHTTPBrowser

HTTPBrowser is capable of capturing keystrokes on victims.

T1059.003
Windows Command Shell
MalwareHTTPBrowser

HTTPBrowser is capable of spawning a reverse shell on a victim.

T1059.003
Windows Command Shell
MalwarePlugX

PlugX allows actors to spawn a reverse shell on a victim.

T1070.006
Timestomp
MalwareOwaAuth

OwaAuth has a command to timestop a file or directory.

T1071.001
Web Protocols
MalwarePlugX

PlugX can be configured to use HTTP for command and control. PlugX has also used HTTPS for C2.

T1071.001
Web Protocols
MalwareOwaAuth

OwaAuth uses incoming HTTP requests with a username keyword and commands and handles them as instructions to perform actions.

T1071.001
Web Protocols
MalwareHTTPBrowser

HTTPBrowser has used HTTP and HTTPS for command and control.

T1071.004
DNS
MalwareHTTPBrowser

HTTPBrowser has used DNS for command and control.

T1071.004
DNS
MalwarePlugX

PlugX can be configured to use DNS for command and control.

T1078
Valid Accounts
GroupThreat Group-3390

Threat Group-3390 actors obtain legitimate credentials using a variety of methods and use them to further lateral movement on victim networks.

T1083
File and Directory Discovery
MalwareHTTPBrowser

HTTPBrowser is capable of listing files, folders, and drives on a victim.

T1083
File and Directory Discovery
MalwareOwaAuth

OwaAuth has a command to list its directory and logical drives.

T1095
Non-Application Layer Protocol
MalwarePlugX

PlugX can be configured to use raw TCP or UDP for command and control.

T1105
Ingress Tool Transfer
GroupThreat Group-3390

Threat Group-3390 has downloaded additional malware and tools, including through the use of `certutil`, onto a compromised host .

T1105
Ingress Tool Transfer
MalwareHTTPBrowser

HTTPBrowser is capable of writing a file to the compromised system from the C2 server.

T1133
External Remote Services
GroupThreat Group-3390

Threat Group-3390 actors look for and use VPN profiles during an operation to access the network using external VPN services. Threat Group-3390 has also obtained OWA account credentials during intrusions that it subsequently used to attempt to regain access when evicted from a victim network.

T1189
Drive-by Compromise
GroupThreat Group-3390

Threat Group-3390 has extensively used strategic web compromises to target victims.

T1505.003
Web Shell
MalwareOwaAuth

OwaAuth is a Web shell that appears to be exclusively used by Threat Group-3390. It is installed as an ISAPI filter on Exchange servers and shares characteristics with the China Chopper Web shell.

T1505.003
Web Shell
MalwareASPXSpy

ASPXSpy is a Web shell. The ASPXTool version used by Threat Group-3390 has been deployed to accessible servers running Internet Information Services (IIS).

T1505.004
IIS Components
MalwareOwaAuth

OwaAuth has been loaded onto Exchange servers and disguised as an ISAPI filter (owaauth.dll). The IIS w3wp.exe process then loads the malicious DLL.

T1560.003
Archive via Custom Method
MalwareOwaAuth

OwaAuth DES-encrypts captured credentials using the key 12345678 before writing the credentials to a log file.

T1574.001
DLL
GroupThreat Group-3390

Threat Group-3390 has performed DLL search order hijacking to execute their payload. Threat Group-3390 has also used DLL side-loading, including by using legitimate Kaspersky antivirus variants as well as `rc.exe`, a legitimate Microsoft Resource Compiler.

T1574.001
DLL
MalwarePlugX

PlugX has the ability to use DLL search order hijacking for installation on targeted systems. PlugX has also used DLL side-loading to evade anti-virus. PlugX has also used a legitimately signed executable to side-load a malicious payload within a DLL file.

T1574.001
DLL
MalwareHTTPBrowser

HTTPBrowser abuses the Windows DLL load order by using a legitimate Symantec anti-virus binary, VPDN_LU.exe, to load a malicious DLL that mimics a legitimate Symantec DLL, navlu.dll. HTTPBrowser has also used DLL side-loading.

T1588.002
Tool
GroupThreat Group-3390

Threat Group-3390 has obtained and used tools such as Impacket, pwdump, Mimikatz, gsecdump, NBTscan, and Windows Credential Editor.

T1608.002
Upload Tool
GroupThreat Group-3390

Threat Group-3390 has staged tools, including gsecdump and WCE, on previously compromised websites.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.