Gruzweig, J. et al. (2021, March 2). Operation Exchange Marauder: Active Exploitation of Multiple Zero-Day Microsoft Exchange Vulnerabilities. Retrieved March 3, 2021.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupHAFNIUM | HAFNIUM has used |
| T1003.003 NTDS |
GroupHAFNIUM | HAFNIUM has stolen copies of the Active Directory database (NTDS.DIT). |
| T1059.001 PowerShell |
GroupHAFNIUM | HAFNIUM has used the Exchange Power Shell module |
| T1098 Account Manipulation |
GroupHAFNIUM | HAFNIUM has granted privileges to domain accounts and reset the password for default admin accounts. |
| T1114.002 Remote Email Collection |
GroupHAFNIUM | HAFNIUM has used web shells and MSGraph to export mailbox data. |
| T1136.002 Domain Account |
GroupHAFNIUM | HAFNIUM has created domain accounts. |
| T1190 Exploit Public-Facing Application |
GroupHAFNIUM | HAFNIUM has exploited multiple vulnerabilities to compromise edge devices and on-premises versions of Microsoft Exchange Server. |
| T1218.011 Rundll32 |
GroupHAFNIUM | HAFNIUM has used |
| T1505.003 Web Shell |
GroupHAFNIUM | HAFNIUM has deployed multiple web shells on compromised servers including SIMPLESEESHARP, SPORTSBALL, China Chopper, and ASPXSpy. |
| T1560.001 Archive via Utility |
GroupHAFNIUM | HAFNIUM has used 7-Zip and WinRAR to compress stolen files for exfiltration. |
| T1589.002 Email Addresses |
GroupHAFNIUM | HAFNIUM has collected e-mail addresses for users they intended to target. |
| T1590 Gather Victim Network Information |
GroupHAFNIUM | HAFNIUM gathered the fully qualified domain names (FQDNs) for targeted Exchange servers in the victim's environment. |
| T1590.005 IP Addresses |
GroupHAFNIUM | HAFNIUM has obtained IP addresses for publicly-accessible Exchange servers. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.