Vyacheslav Kopeytsev and Seongsu Park. (2021, February 25). Lazarus targets defense industry with ThreatNeedle. Retrieved October 27, 2021.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareThreatNeedle | ThreatNeedle can collect data and files from a compromised host. |
| T1005 Data from Local System |
GroupLazarus Group | Lazarus Group has collected data and files from compromised networks. |
| T1021.004 SSH |
GroupLazarus Group | Lazarus Group used SSH and the PuTTy PSCP utility to gain access to a restricted segment of a compromised network. |
| T1027.011 Fileless Storage |
MalwareThreatNeedle | ThreatNeedle can save its configuration data as a RC4-encrypted Registry key under `HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\GameCon`. |
| T1027.013 Encrypted/Encoded File |
MalwareThreatNeedle | ThreatNeedle has been compressed and obfuscated using RC4, AES, or XOR. |
| T1027.015 Compression |
MalwareThreatNeedle | ThreatNeedle has been compressed and obfuscated. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareThreatNeedle | ThreatNeedle chooses its payload creation path from a randomly selected service name from netsvc. |
| T1046 Network Service Discovery |
GroupLazarus Group | Lazarus Group has used nmap from a router VM to scan ports on systems within the restricted segment of an enterprise network. |
| T1047 Windows Management Instrumentation |
GroupLazarus Group | Lazarus Group has used WMIC for discovery as well as to execute payloads for persistence and lateral movement. |
| T1049 System Network Connections Discovery |
GroupLazarus Group | Lazarus Group has used |
| T1070.003 Clear Command History |
GroupLazarus Group | Lazarus Group has routinely deleted log files on a compromised router, including automatic log deletion through the use of the logrotate utility. |
| T1078 Valid Accounts |
GroupLazarus Group | Lazarus Group has used administrator credentials to gain access to restricted network segments. |
| T1082 System Information Discovery |
MalwareThreatNeedle | ThreatNeedle can collect system profile information from a compromised host. |
| T1083 File and Directory Discovery |
MalwareThreatNeedle | ThreatNeedle can obtain file and directory information. |
| T1090.001 Internal Proxy |
GroupLazarus Group | Lazarus Group has used a compromised router to serve as a proxy between a victim network's corporate and restricted segments. |
| T1105 Ingress Tool Transfer |
MalwareThreatNeedle | ThreatNeedle can download additional tools to enable lateral movement. |
| T1105 Ingress Tool Transfer |
GroupLazarus Group | Lazarus Group has downloaded files, malware, and tools from its C2 onto a compromised host. |
| T1112 Modify Registry |
MalwareThreatNeedle | ThreatNeedle can modify the Registry to save its configuration data as the following RC4-encrypted Registry key: `HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\GameCon`. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareThreatNeedle | ThreatNeedle can decrypt its payload using RC4, AES, or one-byte XORing. |
| T1204.002 Malicious File |
MalwareThreatNeedle | ThreatNeedle relies on a victim to click on a malicious document for initial execution. |
| T1204.002 Malicious File |
GroupLazarus Group | Lazarus Group has attempted to get users to launch a malicious Microsoft Word attachment delivered via a spearphishing email. |
| T1543.003 Windows Service |
MalwareThreatNeedle | ThreatNeedle can run in memory and register its payload as a Windows service. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareThreatNeedle | ThreatNeedle can be loaded into the Startup folder (`%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\OneDrives.lnk`) as a Shortcut file for persistence. |
| T1557.001 Name Resolution Poisoning and SMB Relay |
GroupLazarus Group | Lazarus Group executed Responder using the command |
| T1566.001 Spearphishing Attachment |
GroupLazarus Group | Lazarus Group has targeted victims with spearphishing emails containing malicious Microsoft Word documents. |
| T1566.001 Spearphishing Attachment |
MalwareThreatNeedle | ThreatNeedle has been distributed via a malicious Word document within a spearphishing email. |
| T1566.002 Spearphishing Link |
GroupLazarus Group | Lazarus Group has sent malicious links to victims via email. |
| T1584.004 Server |
GroupLazarus Group | Lazarus Group has compromised servers to stage malicious tools. |
| T1585.002 Email Accounts |
GroupLazarus Group | Lazarus Group has created new email accounts for spearphishing operations. |
| T1588.002 Tool |
GroupLazarus Group | Lazarus Group has obtained a variety of tools for their operations, including Responder and PuTTy PSCP. |
| T1589.002 Email Addresses |
GroupLazarus Group | Lazarus Group collected email addresses belonging to various departments of a targeted organization which were used in follow-on phishing campaigns. |
| T1591 Gather Victim Org Information |
GroupLazarus Group | Lazarus Group has studied publicly available information about a targeted organization to tailor spearphishing efforts against specific departments and/or individuals. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.