ATT&CKReferencesCylance Dust Storm

Cylance Dust Storm

Gross, J. (2016, February 23). Operation Dust Storm. Retrieved December 22, 2021.

Open the source

Techniques2

Groups0

None recorded.

Software4

Campaigns1

Procedure examples82

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareMis-Type

Mis-Type has collected files and data from a compromised host.

T1005
Data from Local System
MalwareMisdat

Misdat has collected files and data from a compromised host.

T1007
System Service Discovery
MalwareS-Type

S-Type runs the command net start on a victim.

T1007
System Service Discovery
MalwareZLib

ZLib has the ability to discover and manipulate Windows services.

T1008
Fallback Channels
MalwareMis-Type

Mis-Type first attempts to use a Base64-encoded network protocol over a raw TCP socket for C2, and if that method fails, falls back to a secondary HTTP-based protocol to communicate to an alternate C2 server.

T1008
Fallback Channels
MalwareS-Type

S-Type primarily uses port 80 for C2, but falls back to ports 443 or 8080 if initial communication fails.

T1016
System Network Configuration Discovery
MalwareS-Type

S-Type has used `ipconfig /all` on a compromised host.

T1016
System Network Configuration Discovery
MalwareMis-Type

Mis-Type may create a file containing the results of the command cmd.exe /c ipconfig /all.

T1027.002
Software Packing
CampaignOperation Dust Storm

For Operation Dust Storm, the threat actors used UPX to pack some payloads.

T1027.002
Software Packing
MalwareMisdat

Misdat was typically packed using UPX.

T1027.002
Software Packing
MalwareS-Type

Some S-Type samples have been packed with UPX.

T1027.013
Encrypted/Encoded File
CampaignOperation Dust Storm

During Operation Dust Storm, the threat actors encoded some payloads with a single-byte XOR, both skipping the key itself and zeroing in an attempt to avoid exposing the key; other payloads were Base64-encoded.

T1033
System Owner/User Discovery
MalwareMis-Type

Mis-Type runs tests to determine the privilege level of the compromised user.

T1033
System Owner/User Discovery
MalwareS-Type

S-Type has run tests to determine the privilege level of the compromised user.

T1036
Masquerading
CampaignOperation Dust Storm

For Operation Dust Storm, the threat actors disguised some executables as JPG files.

T1036.005
Match Legitimate Resource Name or Location
MalwareS-Type

S-Type may save itself as a file named `msdtc.exe`, which is also the name of the legitimate Microsoft Distributed Transaction Coordinator service binary.

T1036.005
Match Legitimate Resource Name or Location
MalwareZLib

ZLib mimics the resource version information of legitimate Realtek Semiconductor, Nvidia, or Synaptics modules.

T1036.005
Match Legitimate Resource Name or Location
MalwareMis-Type

Mis-Type saves itself as a file named `msdtc.exe`, which is also the name of the legitimate Microsoft Distributed Transaction Coordinator service binary.

T1036.005
Match Legitimate Resource Name or Location
MalwareMisdat

Misdat saves itself as a file named `msdtc.exe`, which is also the name of the legitimate Microsoft Distributed Transaction Coordinator service binary.

T1041
Exfiltration Over C2 Channel
MalwareS-Type

S-Type has uploaded data and files from a compromised host to its C2 servers.

T1041
Exfiltration Over C2 Channel
MalwareMisdat

Misdat has uploaded files and data to its C2 servers.

T1041
Exfiltration Over C2 Channel
MalwareZLib

ZLib has sent data and files from a compromised host to its C2 servers.

T1041
Exfiltration Over C2 Channel
MalwareMis-Type

Mis-Type has transmitted collected files and data to its C2 server.

T1055
Process Injection
MalwareMis-Type

Mis-Type has been injected directly into a running process, including `explorer.exe`.

T1059.003
Windows Command Shell
MalwareMis-Type

Mis-Type has used `cmd.exe` to run commands on a compromised host.

T1059.003
Windows Command Shell
MalwareS-Type

S-Type has provided the ability to execute shell commands on a compromised host.

T1059.003
Windows Command Shell
MalwareMisdat

Misdat is capable of providing shell functionality to the attacker to execute commands.

T1059.003
Windows Command Shell
MalwareZLib

ZLib has the ability to execute shell commands.

T1059.005
Visual Basic
CampaignOperation Dust Storm

During Operation Dust Storm, the threat actors used Visual Basic scripts.

T1059.007
JavaScript
CampaignOperation Dust Storm

During Operation Dust Storm, the threat actors used JavaScript code.

T1070.004
File Deletion
MalwareS-Type

S-Type has deleted files it has created on a compromised host.

T1070.004
File Deletion
MalwareMisdat

Misdat is capable of deleting the backdoor file.

T1070.006
Timestomp
MalwareMisdat

Many Misdat samples were programmed using Borland Delphi, which will mangle the default PE compile timestamp of a file.

T1070.009
Clear Persistence
MalwareS-Type

S-Type has deleted accounts it has created.

T1070.009
Clear Persistence
MalwareMisdat

Misdat is capable of deleting Registry keys used for persistence.

T1071.001
Web Protocols
MalwareZLib

ZLib communicates over HTTP for C2.

T1071.001
Web Protocols
MalwareS-Type

S-Type uses HTTP for C2.

T1071.001
Web Protocols
MalwareMis-Type

Mis-Type network traffic can communicate over HTTP.

T1074.001
Local Data Staging
MalwareMis-Type

Mis-Type has temporarily stored collected information to the files `“%AppData%\{Unique Identifier}\HOSTRURKLSR”` and `“%AppData%\{Unique Identifier}\NEWERSSEMP”`.

T1082
System Information Discovery
MalwareMis-Type

The initial beacon packet for Mis-Type contains the operating system version and file system of the victim.

T1082
System Information Discovery
MalwareZLib

ZLib has the ability to enumerate system information.

T1082
System Information Discovery
MalwareS-Type

The initial beacon packet for S-Type contains the operating system version and file system of the victim.

T1082
System Information Discovery
MalwareMisdat

The initial beacon packet for Misdat contains the operating system version of the victim.

T1083
File and Directory Discovery
MalwareZLib

ZLib has the ability to enumerate files and drives.

T1083
File and Directory Discovery
MalwareMisdat

Misdat is capable of running commands to obtain a list of files and directories, as well as enumerating logical drives.

T1087.001
Local Account
MalwareS-Type

S-Type has run the command `net user` on a victim.

T1087.001
Local Account
MalwareMis-Type

Mis-Type may create a file containing the results of the command cmd.exe /c net user {Username}.

T1095
Non-Application Layer Protocol
MalwareMis-Type

Mis-Type network traffic can communicate over a raw socket.

T1095
Non-Application Layer Protocol
MalwareMisdat

Misdat network traffic communicates over a raw socket.

T1105
Ingress Tool Transfer
MalwareS-Type

S-Type can download additional files onto a compromised host.

Showing the first 50.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.