ATT&CKCampaignsFrankenstein

Frankenstein

C0001

Campaign, Jan 2019 to Apr 2019.View on attack.mitre.org

About this campaign

Frankenstein was described by security researchers as a highly-targeted campaign conducted by moderately sophisticated and highly resourceful threat actors in early 2019. The unidentified actors primarily relied on open source tools, including Empire. The campaign name refers to the actors' ability to piece together several unrelated open-source tool components.

Techniques used27

Procedure examples27

TechniqueProcedure example
T1005
Data from Local System

During Frankenstein, the threat actors used Empire to gather various local system information.

T1016
System Network Configuration Discovery

During Frankenstein, the threat actors used Empire to find the public IP address of a compromised system.

T1020
Automated Exfiltration

During Frankenstein, the threat actors collected information via Empire, which was automatically sent back to the adversary's C2.

T1027.010
Command Obfuscation

During Frankenstein, the threat actors ran encoded commands from the command line.

T1033
System Owner/User Discovery

During Frankenstein, the threat actors used Empire to enumerate hosts and gather username, machine name, and administrative permissions information.

T1036.004
Masquerade Task or Service

During Frankenstein, the threat actors named a malicious scheduled task "WinUpdate" for persistence.

T1041
Exfiltration Over C2 Channel

During Frankenstein, the threat actors collected information via Empire, which sent the data back to the adversary's C2.

T1047
Windows Management Instrumentation

During Frankenstein, the threat actors used WMI queries to check if various security applications were running as well as to determine the operating system version.

T1053.005
Scheduled Task

During Frankenstein, the threat actors established persistence through a scheduled task using the command: `/Create /F /SC DAILY /ST 09:00 /TN WinUpdate /TR`, named "WinUpdate"

T1057
Process Discovery

During Frankenstein, the threat actors used Empire to obtain a list of all running processes.

T1059.001
PowerShell

During Frankenstein, the threat actors used PowerShell to run a series of Base64-encoded commands that acted as a stager and enumerated hosts.

T1059.003
Windows Command Shell

During Frankenstein, the threat actors ran a command script to set up persistence as a scheduled task named "WinUpdate", as well as other encoded commands from the command-line

T1059.005
Visual Basic

During Frankenstein, the threat actors used Word documents that prompted the victim to enable macros and run a Visual Basic script.

T1071.001
Web Protocols

During Frankenstein, the threat actors used HTTP GET requests for C2.

T1082
System Information Discovery

During Frankenstein, the threat actors used Empire to obtain the compromised machine's name.

View all 27 procedure examples

Attributed groups0

MITRE does not attribute this campaign to a group.

Software1

References1

  1. Talos Frankenstein June 2019 Open source
    Adamitis, D. et al. (2019, June 4). It's alive: Threat actors cobble together open-source pieces into monstrous Frankenstein campaign. Retrieved May 11, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.