ATT&CKReferencesrapid7-email-bombing

rapid7-email-bombing

Tyler McGraw, Thomas Elkins, and Evan McCann. (2024, May 10). Ongoing Social Engineering Campaign Linked to Black Basta Ransomware Operators. Retrieved January 31, 2025.

Open the source

Techniques1

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples22

TechniqueUsed byProcedure example
T1021.002
SMB/Windows Admin Shares
GroupStorm-1811

Storm-1811 has attempted to move laterally in victim environments via SMB using Impacket.

T1027.013
Encrypted/Encoded File
GroupStorm-1811

Storm-1811 XOR encodes a Cobalt Strike installation payload in a DLL file that is decoded with a hardcoded key when called by a legitimate 7zip installation process.

T1033
System Owner/User Discovery
GroupStorm-1811

Storm-1811 has used `whoami.exe` to determine if the active user on a compromised system is an administrator.

T1036
Masquerading
GroupStorm-1811

Storm-1811 has prompted users to download and execute batch scripts that masquerade as legitimate update files during initial access and social engineering operations.

T1036.005
Match Legitimate Resource Name or Location
GroupStorm-1811

Storm-1811 has disguised Cobalt Strike installers as a malicious DLL masquerading as part of a legitimate 7zip installation package.

T1048.002
Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
GroupStorm-1811

Storm-1811 has exfiltrated captured user credentials via Secure Copy Protocol (SCP).

T1056
Input Capture
GroupStorm-1811

Storm-1811 has used a PowerShell script to capture user credentials after prompting a user to authenticate to run a malicious script masquerading as a legitimate update item.

T1059.001
PowerShell
GroupStorm-1811

Storm-1811 has used PowerShell for multiple purposes, such as using PowerShell scripts executing in an infinite loop to create an SSH connection to a command and control server.

T1059.003
Windows Command Shell
GroupStorm-1811

Storm-1811 has used multiple batch scripts during initial access and subsequent actions on victim machines.

T1074.001
Local Data Staging
GroupStorm-1811

Storm-1811 has locally staged captured credentials for subsequent manual exfiltration.

T1105
Ingress Tool Transfer
GroupStorm-1811

Storm-1811 has used scripted `cURL` commands, BITSAdmin, and other mechanisms to retrieve follow-on batch scripts and tools for execution on victim devices.

T1140
Deobfuscate/Decode Files or Information
GroupStorm-1811

Storm-1811 has distributed password-protected archives such as ZIP files during intrusions.

T1204.002
Malicious File
GroupStorm-1811

Storm-1811 has prompted users to execute downloaded software and payloads as the result of social engineering activity.

T1219.002
Remote Desktop Software
GroupStorm-1811

Storm-1811 has abused multiple types of legitimate remote access software and tools, such as ScreenConnect, NetSupport Manager, and AnyDesk.

T1222.001
Windows Permissions
GroupStorm-1811

Storm-1811 has used `cacls.exe` via batch script to modify file and directory permissions in victim environments.

T1547.001
Registry Run Keys / Startup Folder
GroupStorm-1811

Storm-1811 has created Windows Registry Run keys that execute various batch scripts to establish persistence on victim devices.

T1566.004
Spearphishing Voice
GroupStorm-1811

Storm-1811 has initiated voice calls with victims posing as IT support to prompt users to download and execute scripts and other tools for initial access.

T1570
Lateral Tool Transfer
GroupStorm-1811

Storm-1811 has used the Impacket toolset to move and remotely execute payloads to other hosts in victim networks.

T1574.001
DLL
GroupStorm-1811

Storm-1811 has deployed a malicious DLL (7z.DLL) that is sideloaded by a modified, legitimate installer (7zG.exe) when that installer is executed with an additional command line parameter of `b` at runtime to load a Cobalt Strike beacon payload.

T1583.001
Domains
GroupStorm-1811

Storm-1811 has created domains for use with RMM tools.

T1588.002
Tool
GroupStorm-1811

Storm-1811 acquired various legitimate and malicious tools, such as RMM software and commodity malware packages, for operations.

T1667
Email Bombing
GroupStorm-1811

Storm-1811 has deployed large volumes of non-malicious email spam to victims in order to prompt follow-on interactions with the threat actor posing as IT support or helpdesk to resolve the problem.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.