ATT&CKReferencesGoogle Cloud Mandiant UNC3886 2024

Google Cloud Mandiant UNC3886 2024

Punsaen Boonyakarn, Shawn Chew, Logeswaran Nadarajan, Mathew Potaczek, Jakub Jozwiak, and Alex Marvi. (2024, June 18). Cloaked and Covert: Uncovering UNC3886 Espionage Operations. Retrieved September 24, 2024.

Open the source

Techniques1

Groups0

None recorded.

Software4

Campaigns0

None recorded.

Procedure examples49

TechniqueUsed byProcedure example
T1008
Fallback Channels
GroupUNC3886

UNC3886 has employed layers of redundancy to maintain access to compromised environments including network devices, hypervisors, and virtual machines.

T1014
Rootkit
MalwareREPTILE

REPTILE has the ability to hook kernel functions and modify functions data to achieve rootkit functionality such as hiding processes and network connections.

T1014
Rootkit
GroupUNC3886

UNC3886 has used the publicly available rootkits REPTILE and MEDUSA on targeted VMs.

T1014
Rootkit
MalwareMEDUSA

MEDUSA is a rootkit with command execution and credential logging capabilities.

T1027.013
Encrypted/Encoded File
MalwareMOPSLED

MOPSLED can encrypt configuration files with a custom ChaCha20 algorithm.

T1027.013
Encrypted/Encoded File
MalwareMEDUSA

MEDUSA can XOR encrypt configuration strings.

T1040
Network Sniffing
GroupUNC3886

UNC3886 has used the LOOKOVER sniffer to sniff TACACS+ authentication packets.

T1059.004
Unix Shell
MalwareREPTILE

REPTILE can deploy components automatically with shell scripts.

T1059.004
Unix Shell
MalwareRIFLESPINE

RIFLESPINE can execute commands with `/bin/sh`.

T1059.006
Python
MalwareVIRTUALPIE

VIRTUALPIE is a Python-based backdoor malware.

T1071.001
Web Protocols
MalwareMOPSLED

MOPSLED can communicate to C2 nodes over HTTP.

T1071.001
Web Protocols
MalwareRIFLESPINE

RIFLESPINE can use HTTP `GET` and `PUT` to upload and download files.

T1074.001
Local Data Staging
GroupUNC3886

UNC3886 has staged captured credentials in `var/log/ldapd<unique_keyword>.2.gz`.

T1074.001
Local Data Staging
MalwareRIFLESPINE

RIFLESPINE can stage the output from executed C2 commands to a temporary file.

T1078
Valid Accounts
GroupUNC3886

UNC3886 has used tools to hijack valid SSH accounts.

T1082
System Information Discovery
MalwareRIFLESPINE

RIFLESPINE can collect system information after installation on infected systems.

T1095
Non-Application Layer Protocol
MalwareMOPSLED

MOPSLED can use a custom binary protocol over TCP for C2 communication.

T1095
Non-Application Layer Protocol
MalwareREPTILE

REPTILE can communicate using TLS over raw TCP.

T1095
Non-Application Layer Protocol
GroupUNC3886

UNC3886 has deployed backdoors that communicate over TCP to compromised network devices and over VMCI to ESXi hosts.

T1102
Web Service
MalwareMOPSLED

MOPSLED can use third-party web services such as GitHub and Google Drive for C2.

T1102.001
Dead Drop Resolver
MalwareMOPSLED

MOPSLED has the ability to retrieve a C2 address from a dead drop URL.

T1102.002
Bidirectional Communication
MalwareRIFLESPINE

RIFLESPINE can retrieve C2 commands from an encrypted file on Google Drive then upload the results of command execution back to Google Drive.

T1105
Ingress Tool Transfer
MalwareRIFLESPINE

RIFLESPINE can download and execute files.

T1140
Deobfuscate/Decode Files or Information
MalwareREPTILE

The REPTILE launcher component can decrypt kernel module code from a file and load it into memory.

T1140
Deobfuscate/Decode Files or Information
MalwareRIFLESPINE

RIFLESPINE can deobfuscate encrypted files prior to execution on targeted hosts.

T1140
Deobfuscate/Decode Files or Information
MalwareMOPSLED

MOPSLED can decrypt obfuscated configuration files.

T1190
Exploit Public-Facing Application
GroupUNC3886

UNC3886 has exploited CVE-2022-42475 in FortiOS SSL VPNs to obtain access.

T1203
Exploitation for Client Execution
GroupUNC3886

UNC3886 has exoloited CVE-2023-34048 to enable command execution on vCenter servers and CVE-2023-20867 in VMware Tools to execute unauthenticated Guest Operations from ESXi hosts to guest VMs.

T1205
Traffic Signaling
MalwareREPTILE

The REPTILE reverse shell component can listen for a specialized packet in TCP, UDP, or ICMP for activation.

T1205.001
Port Knocking
MalwareREPTILE

REPTILE has the ability to control compromised endpoints via port knocking.

T1212
Exploitation for Credential Access
GroupUNC3886

UNC3886 exploited CVE-2022-22948 in VMware vCenter to obtain encrypted credentials from the vCenter postgresDB.

T1543.002
Systemd Service
MalwareRIFLESPINE

RIFLESPINE can create a systemd service file for execution.

T1543.004
Launch Daemon
MalwareREPTILE

The REPTILE launcher can daemonize a process.

T1546.017
Udev Rules
MalwareREPTILE

REPTILE has used udev for persistence.

T1547.006
Kernel Modules and Extensions
MalwareREPTILE

The REPTILE rootkit is implemented as a loadable kernel module (LKM).

T1554
Compromise Host Software Binary
GroupUNC3886

UNC3886 has trojanized Fortinet firmware and replaced the legitimate `/usr/bin/tac_plus` TACACS+ daemon for Linux with a malicious version containing credential logging functionality.

T1560.001
Archive via Utility
GroupUNC3886

UNC3886 has used Gzip and the Windows command `makecab` to compress files and stolen credentials from victim systems.

T1560.003
Archive via Custom Method
GroupUNC3886

UNC3886 has XOR encrypted and Gzip compressed captured credentials.

T1563.001
SSH Hijacking
MalwareMEDUSA

MEDUSA can be configured to capture SSH credentials via SSH hijacking.

T1564.001
Hidden Files and Directories
MalwareREPTILE

REPTILE has the ability to communicate with the kernel-mode component to hide files.

T1567.002
Exfiltration to Cloud Storage
MalwareRIFLESPINE

RIFLESPINE can upload results from executed C2 commands to cloud storage.

T1573.001
Symmetric Cryptography
MalwareVIRTUALPIE

VIRTUALPIE can use a custom RC4 encrypted protocol for C2 communications.

T1573.001
Symmetric Cryptography
MalwareRIFLESPINE

RIFLESPINE can use the AES algorithm to encrypt C2 data.

T1573.002
Asymmetric Cryptography
MalwareREPTILE

REPTILE can use TLS over raw TCP for secure C2.

T1574.006
Dynamic Linker Hijacking
MalwareMEDUSA

MEDUSA can execute code through dynamic linker hijacking of the `LD_PRELOAD` library.

T1587.004
Exploits
GroupUNC3886

UNC3886 has used zero-day vulnerabilities CVE-2022-41328 against FortiOS and CVE-2023-20867 and CVE-2023-34048 against VMware vCenter.

T1588.001
Malware
GroupUNC3886

UNC3886 has used the publicly available rootkits REPTILE and MEDUSA.

T1588.004
Digital Certificates
GroupUNC3886

UNC3886 has deployed malware using the victim's legitimate TLS certificate obtained from a compromised FortiGate device.

T1675
ESXi Administration Command
GroupUNC3886

UNC3886 used `vmtoolsd.exe` to run commands on guest virtual machines from a compromised ESXi host.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.