Mark-of-the-Web Bypass

T1553.005

Sub-technique of T1553 Subvert Trust Controls.View on attack.mitre.org

About this technique

Adversaries may abuse specific file formats to subvert Mark-of-the-Web (MOTW) controls. In Windows, when files are downloaded from the Internet, they are tagged with a hidden NTFS Alternate Data Stream (ADS) named Zone.Identifier with a specific value known as the MOTW. Files that are tagged with MOTW are protected and cannot perform certain actions. For example, starting in MS Office 10, if a MS Office file has the MOTW, it will open in Protected View. Executables tagged with the MOTW will be processed by Windows Defender SmartScreen that compares files with an allowlist of well-known executables. If the file is not known/trusted, SmartScreen will prevent the execution and warn the user not to run it.

Adversaries may abuse container files such as compressed/archive (.arj, .gzip) and/or disk image (.iso, .vhd) file formats to deliver malicious payloads that may not be tagged with MOTW. Container files downloaded from the Internet will be marked with MOTW but the files within may not inherit the MOTW after the container files are extracted and/or mounted. MOTW is a NTFS feature and many container files do not support NTFS alternative data streams. After a container file is extracted and/or mounted, the files contained within them may be treated as local files on disk and run without protections.

Detection rules11

Rules on DetectionCode tagged with T1553.005.

Sigma6

Splunk5

RuleTypeRiskData source
Windows Advanced Installer MSIX with AI_STUBS ExecutionTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows AppX Deployment Full Trust Package InstallationHuntingNULLWindows Event Log AppXDeployment-Server 400
Windows AppX Deployment Unsigned Package InstallationTTPNULLWindows Event Log AppXDeployment-Server 855
Windows Developer-Signed MSIX Package InstallationAnomalyNULLWindows Event Log AppXDeployment-Server 855
Windows Mark Of The Web BypassTTPNULLSysmon EventID 23, Sysmon EventID 26

Groups3

Software2

Campaigns0

None recorded.

Procedure examples5

Groups3

Used byProcedure example
GroupAPT29

APT29 has embedded ISO images and VHDX files in HTML to evade Mark-of-the-Web.

GroupAPT38

APT38 has used ISO and VHD files to deploy malware and to bypass Mark-of-the-Web (MOTW) security measures.

GroupTA505

TA505 has used .iso files to deploy malicious .lnk files.

Software2

Used byProcedure example
MalwareAmadey

Amadey has modified the `:Zone.Identifier` in the ADS area to zero.

MalwareQakBot

QakBot has been packaged in ISO files in order to bypass Mark of the Web (MOTW) security measures.

References4

  1. Beek Use of VHD Dec 2020 Open source
    Beek, C. (2020, December 3). Investigating the Use of VHD Files By Cybercriminals. Retrieved November 17, 2024.
  2. Intezer Russian APT Dec 2020 Open source
    Kennedy, J. (2020, December 9). A Zebra in Gopher's Clothing: Russian APT Uses COVID-19 Lures to Deliver Zebrocy. Retrieved February 22, 2021.
  3. Microsoft Zone.Identifier 2020 Open source
    Microsoft. (2020, August 31). Zone.Identifier Stream Name. Retrieved February 22, 2021.
  4. Outflank MotW 2020 Open source
    Hegt, S. (2020, March 30). Mark-of-the-Web from a red team’s perspective. Retrieved February 22, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.