Threat group.View on attack.mitre.org
ZIRCONIUM is a threat group operating out of China, active since at least 2017, that has targeted individuals associated with the 2020 US presidential election and prominent leaders in the international affairs community.
| Technique | Procedure example |
|---|---|
| T1012 Query Registry |
ZIRCONIUM has used a tool to query the Registry for proxy settings. |
| T1016 System Network Configuration Discovery |
ZIRCONIUM has used a tool to enumerate proxy settings in the target environment. |
| T1027.002 Software Packing |
ZIRCONIUM has used multi-stage packers for exploit code. |
| T1033 System Owner/User Discovery |
ZIRCONIUM has used a tool to capture the username on a compromised host in order to register it with C2. |
| T1036 Masquerading |
ZIRCONIUM has spoofed legitimate applications in phishing lures and changed file extensions to conceal installation of malware. |
| T1036.004 Masquerade Task or Service |
ZIRCONIUM has created a run key named |
| T1041 Exfiltration Over C2 Channel |
ZIRCONIUM has exfiltrated files via the Dropbox API C2. |
| T1059.003 Windows Command Shell |
ZIRCONIUM has used a tool to open a Windows Command Shell on a remote host. |
| T1059.006 Python |
ZIRCONIUM has used Python-based implants to interact with compromised hosts. |
| T1068 Exploitation for Privilege Escalation |
ZIRCONIUM has exploited CVE-2017-0005 for local privilege escalation. |
| T1082 System Information Discovery |
ZIRCONIUM has used a tool to capture the processor architecture of a compromised host in order to register it with C2. |
| T1090.003 Multi-hop Proxy |
ZIRCONIUM has utilized an ORB (operational relay box) network – consisting compromised devices such as small office and home office (SOHO) routers, IoT devices, and leased virtual private servers (VPS) – to proxy traffic. |
| T1102.002 Bidirectional Communication |
ZIRCONIUM has used Dropbox for C2 allowing upload and download of files as well as execution of arbitrary commands. |
| T1105 Ingress Tool Transfer |
ZIRCONIUM has used tools to download malicious files to compromised hosts. |
| T1124 System Time Discovery |
ZIRCONIUM has used a tool to capture the time on a compromised host in order to register it with C2. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.