ATT&CKReferencesDOJ GRU Indictment Jul 2018

DOJ GRU Indictment Jul 2018

Mueller, R. (2018, July 13). Indictment - United States of America vs. VIKTOR BORISOVICH NETYKSHO, et al. Retrieved November 17, 2024.

Open the source

Techniques2

Groups1

Software1

Campaigns0

None recorded.

Procedure examples18

TechniqueUsed byProcedure example
T1003
OS Credential Dumping
GroupAPT28

APT28 regularly deploys both publicly available (ex: Mimikatz) and custom password retrieval tools on victims.

T1003.001
LSASS Memory
GroupAPT28

APT28 regularly deploys both publicly available (ex: Mimikatz) and custom password retrieval tools on victims. They have also dumped the LSASS process memory using the MiniDump function.

T1005
Data from Local System
GroupAPT28

APT28 has retrieved internal documents from machines inside victim environments, including by using Forfiles to stage documents before exfiltration.

T1056.001
Keylogging
MalwareCHOPSTICK

CHOPSTICK is capable of performing keylogging.

T1056.001
Keylogging
GroupAPT28

APT28 has used tools to perform keylogging.

T1070.004
File Deletion
GroupAPT28

APT28 has intentionally deleted computer files to cover their tracks, including with use of the program CCleaner.

T1078
Valid Accounts
GroupAPT28

APT28 has used legitimate credentials to gain initial access, maintain access, and exfiltrate data from a victim network. The group has specifically used credentials stolen through a spearphishing email to login to the DCCC network. The group has also leveraged default manufacturer's passwords to gain initial access to corporate networks via IoT devices such as a VOIP phone, printer, and video decoder.

T1083
File and Directory Discovery
GroupAPT28

APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection. The group also searched a compromised DCCC computer for specific terms.

T1090.002
External Proxy
GroupAPT28

APT28 used other victims as proxies to relay command traffic, for instance using a compromised Georgian military email server as a hop point to NATO victims. The group has also used a tool that acts as a proxy to allow C2 even if the victim is behind a router. APT28 has also used a machine to relay and obscure communications between CHOPSTICK and their server.

T1113
Screen Capture
MalwareCHOPSTICK

CHOPSTICK has the capability to capture screenshots.

T1113
Screen Capture
GroupAPT28

APT28 has used tools to take screenshots from victims.

T1114.002
Remote Email Collection
GroupAPT28

APT28 has collected emails from victim Microsoft Exchange servers.

T1119
Automated Collection
GroupAPT28

APT28 used a publicly available tool to gather and compress multiple documents on the DCCC and DNC networks.

T1199
Trusted Relationship
GroupAPT28

Once APT28 gained access to the DCCC network, the group then proceeded to use that access to compromise the DNC network.

T1560
Archive Collected Data
GroupAPT28

APT28 used a publicly available tool to gather and compress multiple documents on the DCCC and DNC networks.

T1566.001
Spearphishing Attachment
GroupAPT28

APT28 sent spearphishing emails containing malicious Microsoft Office and RAR attachments.

T1598.003
Spearphishing Link
GroupAPT28

APT28 has conducted credential phishing campaigns with links that redirect to credential harvesting sites.

T1685.005
Clear Windows Event Logs
GroupAPT28

APT28 has cleared event logs, including by using the commands wevtutil cl System and wevtutil cl Security.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.