ATT&CKReferencesUS-CERT TA18-074A

US-CERT TA18-074A

US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

Open the source

Techniques2

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples42

TechniqueUsed byProcedure example
T1003.002
Security Account Manager
GroupDragonfly

Dragonfly has dropped and executed SecretsDump to dump password hashes.

T1003.003
NTDS
GroupDragonfly

Dragonfly has dropped and executed SecretsDump to dump password hashes. They also obtained ntds.dit from domain controllers.

T1003.004
LSA Secrets
GroupDragonfly

Dragonfly has dropped and executed SecretsDump to dump password hashes.

T1005
Data from Local System
GroupDragonfly

Dragonfly has collected data from local victim systems.

T1012
Query Registry
GroupDragonfly

Dragonfly has queried the Registry to identify victim information.

T1016
System Network Configuration Discovery
GroupDragonfly

Dragonfly has used batch scripts to enumerate network information, including information about trusts, zones, and the domain.

T1018
Remote System Discovery
GroupDragonfly

Dragonfly has likely obtained a list of hosts in the victim environment.

T1021.001
Remote Desktop Protocol
GroupDragonfly

Dragonfly has moved laterally via RDP.

T1033
System Owner/User Discovery
GroupDragonfly

Dragonfly used the command query user on victim hosts.

T1036.010
Masquerade Account Name
GroupDragonfly

Dragonfly has created accounts disguised as legitimate backup and service accounts as well as an email administration account.

T1053.005
Scheduled Task
GroupDragonfly

Dragonfly has used scheduled tasks to automatically log out of created accounts every 8 hours as well as to execute malicious files.

T1059
Command and Scripting Interpreter
GroupDragonfly

Dragonfly has used the command line for execution.

T1059.001
PowerShell
GroupDragonfly

Dragonfly has used PowerShell scripts for execution.

T1059.003
Windows Command Shell
GroupDragonfly

Dragonfly has used various types of scripting to perform operations, including batch scripts.

T1059.006
Python
GroupDragonfly

Dragonfly has used various types of scripting to perform operations, including Python scripts. The group was observed installing Python 2.7 on a victim.

T1069.002
Domain Groups
GroupDragonfly

Dragonfly has used batch scripts to enumerate administrators and users in the domain.

T1070.004
File Deletion
GroupDragonfly

Dragonfly has deleted many of its files used during operations as part of cleanup, including removing applications and deleting screenshots.

T1071.002
File Transfer Protocols
GroupDragonfly

Dragonfly has used SMB for C2.

T1074.001
Local Data Staging
GroupDragonfly

Dragonfly has created a directory named "out" in the user's %AppData% folder and copied files to it.

T1078
Valid Accounts
GroupDragonfly

Dragonfly has compromised user credentials and used valid accounts for operations.

T1083
File and Directory Discovery
GroupDragonfly

Dragonfly has used a batch script to gather folder and file names from victim hosts.

T1087.002
Domain Account
GroupDragonfly

Dragonfly has used batch scripts to enumerate users on a victim domain controller.

T1098.007
Additional Local or Domain Groups
GroupDragonfly

Dragonfly has added newly created accounts to the administrators group to maintain elevated access.

T1105
Ingress Tool Transfer
GroupDragonfly

Dragonfly has copied and installed tools for operations once in the victim environment.

T1110.002
Password Cracking
GroupDragonfly

Dragonfly has dropped and executed tools used for password cracking, including Hydra and CrackMapExec.

T1112
Modify Registry
GroupDragonfly

Dragonfly has modified the Registry to perform multiple techniques through the use of Reg.

T1113
Screen Capture
GroupDragonfly

Dragonfly has performed screen captures of victims, including by using a tool, scr.exe (which matched the hash of ScreenUtil).

T1114.002
Remote Email Collection
GroupDragonfly

Dragonfly has accessed email accounts using Outlook Web Access.

T1133
External Remote Services
GroupDragonfly

Dragonfly has used VPNs and Outlook Web Access (OWA) to maintain access to victim networks.

T1135
Network Share Discovery
GroupDragonfly

Dragonfly has identified and browsed file servers in the victim network, sometimes , viewing files pertaining to ICS or Supervisory Control and Data Acquisition (SCADA) systems.

T1136.001
Local Account
GroupDragonfly

Dragonfly has created accounts on victims, including administrator accounts, some of which appeared to be tailored to each individual staging target.

T1187
Forced Authentication
GroupDragonfly

Dragonfly has gathered hashed user credentials over SMB using spearphishing attachments with external resource links and by modifying .LNK file icon resources to collect credentials from virtualized systems.

T1189
Drive-by Compromise
GroupDragonfly

Dragonfly has compromised targets via strategic web compromise (SWC) utilizing a custom exploit kit.

T1221
Template Injection
GroupDragonfly

Dragonfly has injected SMB URLs into malicious Word spearphishing attachments to initiate Forced Authentication.

T1505.003
Web Shell
GroupDragonfly

Dragonfly has commonly created Web shells on victims' publicly accessible email and web servers, which they used to maintain access to a victim network and download additional malicious files.

T1547.001
Registry Run Keys / Startup Folder
GroupDragonfly

Dragonfly has added the registry value ntdll to the Registry Run key to establish persistence.

T1560
Archive Collected Data
GroupDragonfly

Dragonfly has compressed data into .zip files prior to exfiltration.

T1564.002
Hidden Users
GroupDragonfly

Dragonfly has modified the Registry to hide created user accounts.

T1598.002
Spearphishing Attachment
GroupDragonfly

Dragonfly has used spearphishing with Microsoft Office attachments to enable harvesting of user credentials.

T1598.003
Spearphishing Link
GroupDragonfly

Dragonfly has used spearphishing with PDF attachments containing malicious links that redirected to credential harvesting websites.

T1685.005
Clear Windows Event Logs
GroupDragonfly

Dragonfly has cleared Windows event logs and other logs produced by tools they used, including system, security, terminal services, remote services, and audit logs. The actors also deleted specific Registry keys.

T1686
Disable or Modify System Firewall
GroupDragonfly

Dragonfly has disabled host-based firewalls. The group has also globally opened port 3389.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.