ATT&CKCampaignsOperation Wocao

Operation Wocao

C0014

Campaign, Dec 2017 to Dec 2019.View on attack.mitre.org

About this campaign

Operation Wocao was a cyber espionage campaign that targeted organizations around the world, including in Brazil, China, France, Germany, Italy, Mexico, Portugal, Spain, the United Kingdom, and the United States. The suspected China-based actors compromised government organizations and managed service providers, as well as aviation, construction, energy, finance, health care, insurance, offshore engineering, software development, and transportation companies.

Security researchers assessed the Operation Wocao actors used similar TTPs and tools as APT20, suggesting a possible overlap. Operation Wocao was named after an observed command line entry by one of the threat actors, possibly out of frustration from losing webshell access.

Techniques used70

Procedure examples70

TechniqueProcedure example
T1001
Data Obfuscation

During Operation Wocao, threat actors encrypted IP addresses used for "Agent" proxy hops with RC4.

T1003.001
LSASS Memory

During Operation Wocao, threat actors used ProcDump to dump credentials from memory.

T1003.006
DCSync

During Operation Wocao, threat actors used Mimikatz's DCSync to dump credentials from the memory of the targeted system.

T1005
Data from Local System

During Operation Wocao, threat actors exfiltrated files and directories of interest from the targeted system.

T1007
System Service Discovery

During Operation Wocao, threat actors used the `tasklist` command to search for one of its backdoors.

T1012
Query Registry

During Operation Wocao, the threat actors executed `/c cd /d c:\windows\temp\ & reg query HKEY_CURRENT_USER\Software\<username>\PuTTY\Sessions\` to detect recent PuTTY sessions, likely to further lateral movement.

T1016
System Network Configuration Discovery

During Operation Wocao, threat actors discovered the local network configuration with `ipconfig`.

T1016.001
Internet Connection Discovery

During Operation Wocao, threat actors used a Visual Basic script that checked for internet connectivity.

T1018
Remote System Discovery

During Operation Wocao, threat actors used `nbtscan` and `ping` to discover remote systems, as well as `dsquery subnet` on a domain controller to retrieve all subnets in the Active Directory.

T1021.002
SMB/Windows Admin Shares

During Operation Wocao, threat actors used Impacket's smbexec.py as well as accessing the C$ and IPC$ shares to move laterally.

T1027.005
Indicator Removal from Tools

During Operation Wocao, threat actors edited variable names within the Impacket suite to avoid automated detection.

T1027.010
Command Obfuscation

During Operation Wocao, threat actors executed PowerShell commands which were encoded or compressed using Base64, zlib, and XOR.

T1033
System Owner/User Discovery

During Operation Wocao, threat actors enumerated sessions and users on a remote host, and identified privileged users logged into a targeted system.

T1036.005
Match Legitimate Resource Name or Location

During Operation Wocao, the threat actors renamed some tools and executables to appear as legitimate programs.

T1041
Exfiltration Over C2 Channel

During Operation Wocao, threat actors used the XServer backdoor to exfiltrate data.

View all 70 procedure examples

Attributed groups0

MITRE does not attribute this campaign to a group.

Software9

References1

  1. FoxIT Wocao December 2019 Open source
    Dantzig, M. v., Schamper, E. (2019, December 19). Operation Wocao: Shining a light on one of China’s hidden hacking groups. Retrieved October 8, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.