Campaign, Sep 2013 to Oct 2019.View on attack.mitre.org
Operation Ghost was an APT29 campaign starting in 2013 that included operations against ministries of foreign affairs in Europe and the Washington, D.C. embassy of a European Union country. During Operation Ghost, APT29 used new families of malware and leveraged web services, steganography, and unique C2 infrastructure for each victim.
| Technique | Procedure example |
|---|---|
| T1001.002 Steganography |
During Operation Ghost, APT29 used steganography to hide the communications between the implants and their C&C servers. |
| T1027.003 Steganography |
During Operation Ghost, APT29 used steganography to hide payloads inside valid images. |
| T1078.002 Domain Accounts |
For Operation Ghost, APT29 used stolen administrator credentials for lateral movement on compromised networks. |
| T1102.002 Bidirectional Communication |
For Operation Ghost, APT29 used social media platforms to hide communications to C2 servers. |
| T1546.003 Windows Management Instrumentation Event Subscription |
During Operation Ghost, APT29 used WMI event subscriptions to establish persistence for malware. |
| T1583.001 Domains |
For Operation Ghost, APT29 registered domains for use in C2 including some crafted to appear as existing legitimate domains. |
| T1585.001 Social Media Accounts |
For Operation Ghost, APT29 registered Twitter accounts to host C2 nodes. |
| T1587.001 Malware |
For Operation Ghost, APT29 used new strains of malware including FatDuke, MiniDuke, RegDuke, and PolyglotDuke. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.