ATT&CKReferencesPWC Cloud Hopper April 2017

PWC Cloud Hopper April 2017

PwC and BAE Systems. (2017, April). Operation Cloud Hopper. Retrieved April 5, 2017.

Open the source

Techniques1

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples11

TechniqueUsed byProcedure example
T1021.001
Remote Desktop Protocol
GroupmenuPass

menuPass has used RDP connections to move across the victim network.

T1021.004
SSH
GroupmenuPass

menuPass has used Putty Secure Copy Client (PSCP) to transfer data.

T1039
Data from Network Shared Drive
GroupmenuPass

menuPass has collected data from remote systems by mounting network shares with net use and using Robocopy to transfer data.

T1049
System Network Connections Discovery
GroupmenuPass

menuPass has used net use to conduct connectivity checks to machines.

T1059.003
Windows Command Shell
GroupmenuPass

menuPass executes commands using a command-line interface and reverse shell. The group has used a modified version of pentesting script wmiexec.vbs to execute commands. menuPass has used malicious macros embedded inside Office documents to execute files.

T1074.001
Local Data Staging
GroupmenuPass

menuPass stages data prior to exfiltration in multi-part archives, often saved in the Recycle Bin.

T1074.002
Remote Data Staging
GroupmenuPass

menuPass has staged data on remote MSP systems or other victim networks prior to exfiltration.

T1078
Valid Accounts
GroupmenuPass

menuPass has used valid accounts including shared between Managed Service Providers and clients to move between the two environments.

T1105
Ingress Tool Transfer
GroupmenuPass

menuPass has installed updates and new malware on victims.

T1560.001
Archive via Utility
GroupmenuPass

menuPass has compressed files before exfiltration using TAR and RAR.

T1574.001
DLL
GroupmenuPass

menuPass has used DLL side-loading to launch versions of Mimikatz and PwDump6 as well as UPPERCUT. menuPass has also used DLL search order hijacking.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.