ATT&CKReferencesSymantec Elfin Mar 2019

Symantec Elfin Mar 2019

Security Response attack Investigation Team. (2019, March 27). Elfin: Relentless Espionage Group Targets Multiple Organizations in Saudi Arabia and U.S.. Retrieved April 10, 2019.

Open the source

Techniques1

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples22

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupAPT33

APT33 has used a variety of publicly available tools like LaZagne, Mimikatz, and ProcDump to dump credentials.

T1003.004
LSA Secrets
GroupAPT33

APT33 has used a variety of publicly available tools like LaZagne to gather credentials.

T1003.005
Cached Domain Credentials
GroupAPT33

APT33 has used a variety of publicly available tools like LaZagne to gather credentials.

T1040
Network Sniffing
GroupAPT33

APT33 has used SniffPass to collect credentials by sniffing network traffic.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
GroupAPT33

APT33 has used FTP to exfiltrate files (separately from the C2 channel).

T1053.005
Scheduled Task
GroupAPT33

APT33 has created a scheduled task to execute a .vbe file multiple times a day.

T1059.001
PowerShell
GroupAPT33

APT33 has utilized PowerShell to download files from the C2 server and run various scripts.

T1071.001
Web Protocols
GroupAPT33

APT33 has used HTTP for command and control.

T1105
Ingress Tool Transfer
GroupAPT33

APT33 has downloaded additional files and programs from its C2 server.

T1203
Exploitation for Client Execution
GroupAPT33

APT33 has attempted to exploit a known vulnerability in WinRAR (CVE-2018-20250), and attempted to gain remote code execution via a security bypass vulnerability (CVE-2017-11774).

T1204.001
Malicious Link
GroupAPT33

APT33 has lured users to click links to malicious HTML applications delivered via spearphishing emails.

T1547.001
Registry Run Keys / Startup Folder
GroupAPT33

APT33 has deployed a tool known as DarkComet to the Startup folder of a victim, and used Registry run keys to gain persistence.

T1552.001
Credentials In Files
GroupAPT33

APT33 has used a variety of publicly available tools like LaZagne to gather credentials.

T1552.006
Group Policy Preferences
GroupAPT33

APT33 has used a variety of publicly available tools like Gpppassword to gather credentials.

T1555
Credentials from Password Stores
GroupAPT33

APT33 has used a variety of publicly available tools like LaZagne to gather credentials.

T1555.003
Credentials from Web Browsers
GroupAPT33

APT33 has used a variety of publicly available tools like LaZagne to gather credentials.

T1560.001
Archive via Utility
GroupAPT33

APT33 has used WinRAR to compress data prior to exfil.

T1561.001
Disk Content Wipe
MalwareStoneDrill

StoneDrill can wipe the accessible physical or logical drives of the infected machine.

T1561.002
Disk Structure Wipe
MalwareStoneDrill

StoneDrill can wipe the master boot record of an infected computer.

T1566.002
Spearphishing Link
GroupAPT33

APT33 has sent spearphishing emails containing links to .hta files.

T1571
Non-Standard Port
GroupAPT33

APT33 has used HTTP over TCP ports 808 and 880 for command and control.

T1588.002
Tool
GroupAPT33

APT33 has obtained and leveraged publicly-available tools for early intrusion activities.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.