Joe Slowik. (2018, October 12). Anatomy of an Attack: Detecting and Defeating CRASHOVERRIDE. Retrieved December 18, 2020.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team used Mimikatz to capture and use legitimate credentials. |
| T1018 Remote System Discovery |
GroupSandworm Team | Sandworm Team has used a tool to query Active Directory using LDAP, discovering information about computers listed in AD. |
| T1018 Remote System Discovery |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team checked for connectivity to resources within the network and used LDAP to query Active Directory, discovering information about computers listed in AD. |
| T1021.002 SMB/Windows Admin Shares |
GroupSandworm Team | Sandworm Team has copied payloads to the `ADMIN$` share of remote systems and run |
| T1021.002 SMB/Windows Admin Shares |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team utilized `net use` to connect to network shares. |
| T1027.002 Software Packing |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team used UPX to pack a copy of Mimikatz. |
| T1036.008 Masquerade File Type |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team masqueraded executables as `.txt` files. |
| T1036.010 Masquerade Account Name |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team created two new accounts, “admin” and “система” (System). |
| T1047 Windows Management Instrumentation |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, WMI in scripts were used for remote execution and system surveys. |
| T1047 Windows Management Instrumentation |
GroupSandworm Team | Sandworm Team has used Impacket’s WMIexec module for remote code execution and VBScript to run WMI queries. |
| T1049 System Network Connections Discovery |
GroupSandworm Team | Sandworm Team had gathered user, IP address, and server data related to RDP sessions on a compromised host. It has also accessed network diagram files useful for understanding how a host's network was configured. |
| T1059.001 PowerShell |
GroupSandworm Team | Sandworm Team has used PowerShell scripts to run a credential harvesting tool in memory to evade defenses. |
| T1059.001 PowerShell |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team used PowerShell scripts to run a credential harvesting tool in memory to evade defenses. |
| T1059.003 Windows Command Shell |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team used the `xp_cmdshell` command in MS-SQL. |
| T1059.005 Visual Basic |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team created VBScripts to run on an SSH server. |
| T1059.005 Visual Basic |
GroupSandworm Team | Sandworm Team has created VBScripts to run an SSH server. |
| T1083 File and Directory Discovery |
GroupSandworm Team | Sandworm Team has enumerated files on a compromised host. |
| T1098 Account Manipulation |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team used the `sp_addlinkedsrvlogin` command in MS-SQL to create a link between a created account and other servers in the network. |
| T1110 Brute Force |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team used a script to attempt RPC authentication against a number of hosts. |
| T1136 Create Account |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team added a login to a SQL Server with `sp_addlinkedsrvlogin`. |
| T1136.002 Domain Account |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team created two new accounts, “admin” and “система” (System). The accounts were then assigned to a domain matching local operation and were delegated new privileges. |
| T1505.001 SQL Stored Procedures |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team used various MS-SQL stored procedures. |
| T1570 Lateral Tool Transfer |
GroupSandworm Team | Sandworm Team has used `move` to transfer files to a network share and has copied payloads--such as Prestige ransomware--to an Active Directory Domain Controller and distributed via the Default Domain Group Policy Object. Additionally, Sandworm Team has transferred an ISO file into the OT network to gain initial access. |
| T1570 Lateral Tool Transfer |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team used `move` to transfer files to a network share. |
| T1685.001 Disable or Modify Windows Event Log |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team disabled event logging on compromised systems. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.