Threat group.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1003.001 LSASS Memory |
Ke3chang has dumped credentials, including by using Mimikatz. |
| T1003.002 Security Account Manager |
Ke3chang has dumped credentials, including by using gsecdump. |
| T1003.003 NTDS |
Ke3chang has used NTDSDump and other password dumping tools to gather credentials. |
| T1003.004 LSA Secrets |
Ke3chang has dumped credentials, including by using gsecdump. |
| T1005 Data from Local System |
Ke3chang gathered information and files from local directories for exfiltration. |
| T1007 System Service Discovery |
Ke3chang performs service discovery using |
| T1016 System Network Configuration Discovery |
Ke3chang has performed local network configuration discovery using |
| T1018 Remote System Discovery |
Ke3chang has used network scanning and enumeration tools, including Ping. |
| T1020 Automated Exfiltration |
Ke3chang has performed frequent and scheduled data exfiltration from compromised networks. |
| T1021.002 SMB/Windows Admin Shares |
Ke3chang actors have been known to copy files to the network shares of other computers to move laterally. |
| T1027 Obfuscated Files or Information |
Ke3chang has used Base64-encoded shellcode strings. |
| T1033 System Owner/User Discovery |
Ke3chang has used implants capable of collecting the signed-in username. |
| T1036.002 Right-to-Left Override |
Ke3chang has used the right-to-left override character in spearphishing attachment names to trick targets into executing .scr and .exe files. |
| T1036.005 Match Legitimate Resource Name or Location |
Ke3chang has dropped their malware into legitimate installed software paths including: `C:\ProgramFiles\Realtek\Audio\HDA\AERTSr.exe`, `C:\Program Files (x86)\Foxit Software\Foxit Reader\FoxitRdr64.exe`, `C:\Program Files (x86)\Adobe\Flash Player\AddIns\airappinstaller\airappinstall.exe`, and `C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd64.exe`. |
| T1041 Exfiltration Over C2 Channel |
Ke3chang transferred compressed and encrypted RAR files containing exfiltration through the established backdoor command and control channel during operations. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.