ATT&CKReferencesKaspersky ThreatNeedle Feb 2021

Kaspersky ThreatNeedle Feb 2021

Vyacheslav Kopeytsev and Seongsu Park. (2021, February 25). Lazarus targets defense industry with ThreatNeedle. Retrieved October 27, 2021.

Open the source

Techniques1

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples32

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareThreatNeedle

ThreatNeedle can collect data and files from a compromised host.

T1005
Data from Local System
GroupLazarus Group

Lazarus Group has collected data and files from compromised networks.

T1021.004
SSH
GroupLazarus Group

Lazarus Group used SSH and the PuTTy PSCP utility to gain access to a restricted segment of a compromised network.

T1027.011
Fileless Storage
MalwareThreatNeedle

ThreatNeedle can save its configuration data as a RC4-encrypted Registry key under `HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\GameCon`.

T1027.013
Encrypted/Encoded File
MalwareThreatNeedle

ThreatNeedle has been compressed and obfuscated using RC4, AES, or XOR.

T1027.015
Compression
MalwareThreatNeedle

ThreatNeedle has been compressed and obfuscated.

T1036.005
Match Legitimate Resource Name or Location
MalwareThreatNeedle

ThreatNeedle chooses its payload creation path from a randomly selected service name from netsvc.

T1046
Network Service Discovery
GroupLazarus Group

Lazarus Group has used nmap from a router VM to scan ports on systems within the restricted segment of an enterprise network.

T1047
Windows Management Instrumentation
GroupLazarus Group

Lazarus Group has used WMIC for discovery as well as to execute payloads for persistence and lateral movement.

T1049
System Network Connections Discovery
GroupLazarus Group

Lazarus Group has used net use to identify and establish a network connection with a remote host.

T1070.003
Clear Command History
GroupLazarus Group

Lazarus Group has routinely deleted log files on a compromised router, including automatic log deletion through the use of the logrotate utility.

T1078
Valid Accounts
GroupLazarus Group

Lazarus Group has used administrator credentials to gain access to restricted network segments.

T1082
System Information Discovery
MalwareThreatNeedle

ThreatNeedle can collect system profile information from a compromised host.

T1083
File and Directory Discovery
MalwareThreatNeedle

ThreatNeedle can obtain file and directory information.

T1090.001
Internal Proxy
GroupLazarus Group

Lazarus Group has used a compromised router to serve as a proxy between a victim network's corporate and restricted segments.

T1105
Ingress Tool Transfer
MalwareThreatNeedle

ThreatNeedle can download additional tools to enable lateral movement.

T1105
Ingress Tool Transfer
GroupLazarus Group

Lazarus Group has downloaded files, malware, and tools from its C2 onto a compromised host.

T1112
Modify Registry
MalwareThreatNeedle

ThreatNeedle can modify the Registry to save its configuration data as the following RC4-encrypted Registry key: `HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\GameCon`.

T1140
Deobfuscate/Decode Files or Information
MalwareThreatNeedle

ThreatNeedle can decrypt its payload using RC4, AES, or one-byte XORing.

T1204.002
Malicious File
MalwareThreatNeedle

ThreatNeedle relies on a victim to click on a malicious document for initial execution.

T1204.002
Malicious File
GroupLazarus Group

Lazarus Group has attempted to get users to launch a malicious Microsoft Word attachment delivered via a spearphishing email.

T1543.003
Windows Service
MalwareThreatNeedle

ThreatNeedle can run in memory and register its payload as a Windows service.

T1547.001
Registry Run Keys / Startup Folder
MalwareThreatNeedle

ThreatNeedle can be loaded into the Startup folder (`%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\OneDrives.lnk`) as a Shortcut file for persistence.

T1557.001
Name Resolution Poisoning and SMB Relay
GroupLazarus Group

Lazarus Group executed Responder using the command [Responder file path] -i [IP address] -rPv on a compromised host to harvest credentials and move laterally.

T1566.001
Spearphishing Attachment
GroupLazarus Group

Lazarus Group has targeted victims with spearphishing emails containing malicious Microsoft Word documents.

T1566.001
Spearphishing Attachment
MalwareThreatNeedle

ThreatNeedle has been distributed via a malicious Word document within a spearphishing email.

T1566.002
Spearphishing Link
GroupLazarus Group

Lazarus Group has sent malicious links to victims via email.

T1584.004
Server
GroupLazarus Group

Lazarus Group has compromised servers to stage malicious tools.

T1585.002
Email Accounts
GroupLazarus Group

Lazarus Group has created new email accounts for spearphishing operations.

T1588.002
Tool
GroupLazarus Group

Lazarus Group has obtained a variety of tools for their operations, including Responder and PuTTy PSCP.

T1589.002
Email Addresses
GroupLazarus Group

Lazarus Group collected email addresses belonging to various departments of a targeted organization which were used in follow-on phishing campaigns.

T1591
Gather Victim Org Information
GroupLazarus Group

Lazarus Group has studied publicly available information about a targeted organization to tailor spearphishing efforts against specific departments and/or individuals.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.