ATT&CKReferencesClearSky Lebanese Cedar Jan 2021

ClearSky Lebanese Cedar Jan 2021

ClearSky Cyber Security. (2021, January). “Lebanese Cedar” APT Global Lebanese Espionage Campaign Leveraging Web Servers. Retrieved February 10, 2021.

Open the source

Techniques1

Groups1

Software2

Campaigns0

None recorded.

Procedure examples22

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareCaterpillar WebShell

Caterpillar WebShell has a module to collect information from the local database.

T1007
System Service Discovery
MalwareCaterpillar WebShell

Caterpillar WebShell can obtain a list of the services from a system.

T1014
Rootkit
MalwareCaterpillar WebShell

Caterpillar WebShell has a module to use a rootkit on a system.

T1016
System Network Configuration Discovery
MalwareCaterpillar WebShell

Caterpillar WebShell can gather the IP address from the victim's machine using the IP config command.

T1033
System Owner/User Discovery
MalwareCaterpillar WebShell

Caterpillar WebShell can obtain a list of user accounts from a victim's machine.

T1041
Exfiltration Over C2 Channel
MalwareCaterpillar WebShell

Caterpillar WebShell can upload files over the C2 channel.

T1046
Network Service Discovery
MalwareCaterpillar WebShell

Caterpillar WebShell has a module to use a port scanner on a system.

T1056.001
Keylogging
MalwareExplosive

Explosive has leveraged its keylogging capabilities to gain access to administrator accounts on target servers.

T1057
Process Discovery
MalwareCaterpillar WebShell

Caterpillar WebShell can gather a list of processes running on the machine.

T1059.003
Windows Command Shell
MalwareCaterpillar WebShell

Caterpillar WebShell can run commands on the compromised asset with CMD functions.

T1069.001
Local Groups
MalwareCaterpillar WebShell

Caterpillar WebShell can obtain a list of local groups of users from a system.

T1082
System Information Discovery
MalwareCaterpillar WebShell

Caterpillar WebShell has a module to gather information from the compromised asset, including the computer version, computer name, IIS version, and more.

T1083
File and Directory Discovery
MalwareCaterpillar WebShell

Caterpillar WebShell can search for files in directories.

T1105
Ingress Tool Transfer
MalwareCaterpillar WebShell

Caterpillar WebShell has a module to download and upload files to the system.

T1105
Ingress Tool Transfer
GroupVolatile Cedar

Volatile Cedar can deploy additional tools.

T1110
Brute Force
MalwareCaterpillar WebShell

Caterpillar WebShell has a module to perform brute force attacks on a system.

T1112
Modify Registry
MalwareCaterpillar WebShell

Caterpillar WebShell has a command to modify a Registry key.

T1190
Exploit Public-Facing Application
GroupVolatile Cedar

Volatile Cedar has targeted publicly facing web servers, with both automatic and manual vulnerability discovery.

T1505.003
Web Shell
GroupVolatile Cedar

Volatile Cedar can inject web shell code into a server.

T1573.001
Symmetric Cryptography
MalwareExplosive

Explosive has encrypted communications with the RC4 method.

T1595.002
Vulnerability Scanning
GroupVolatile Cedar

Volatile Cedar has performed vulnerability scans of the target server.

T1595.003
Wordlist Scanning
GroupVolatile Cedar

Volatile Cedar has used DirBuster and GoBuster to brute force web directories and DNS subdomains.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.