ATT&CKReferencesTrendMicro Pawn Storm Dec 2020

TrendMicro Pawn Storm Dec 2020

Hacquebord, F., Remorin, L. (2020, December 17). Pawn Storm’s Lack of Sophistication as a Strategy. Retrieved January 13, 2021.

Open the source

Techniques1

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples10

TechniqueUsed byProcedure example
T1056.001
Keylogging
GroupAPT28

APT28 has used tools to perform keylogging.

T1059.001
PowerShell
GroupAPT28

APT28 downloads and executes PowerShell scripts and performs PowerShell commands.

T1059.003
Windows Command Shell
GroupAPT28

An APT28 loader Trojan uses a cmd.exe and batch script to run its payload. The group has also used macros to execute payloads.

T1090.003
Multi-hop Proxy
GroupAPT28

APT28 has routed traffic over Tor and VPN servers to obfuscate their activities.

T1102.002
Bidirectional Communication
GroupAPT28

APT28 has used Google Drive for C2.

T1105
Ingress Tool Transfer
GroupAPT28

APT28 has downloaded additional files, including by using a first-stage downloader to contact the C2 server to obtain the second-stage implant.

T1110
Brute Force
GroupAPT28

APT28 can perform brute force attacks to obtain credentials.

T1547.001
Registry Run Keys / Startup Folder
GroupAPT28

APT28 has deployed malware that has copied itself to the startup directory for persistence.

T1566.001
Spearphishing Attachment
GroupAPT28

APT28 sent spearphishing emails containing malicious Microsoft Office and RAR attachments.

T1567
Exfiltration Over Web Service
GroupAPT28

APT28 can exfiltrate data over Google Drive.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.