ATT&CKReferencesZscaler APT31 Covid-19 October 2020

Zscaler APT31 Covid-19 October 2020

Singh, S. and Antil, S. (2020, October 27). APT-31 Leverages COVID-19 Vaccine Theme and Abuses Legitimate Online Services. Retrieved March 24, 2021.

Open the source

Techniques1

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples20

TechniqueUsed byProcedure example
T1012
Query Registry
GroupZIRCONIUM

ZIRCONIUM has used a tool to query the Registry for proxy settings.

T1016
System Network Configuration Discovery
GroupZIRCONIUM

ZIRCONIUM has used a tool to enumerate proxy settings in the target environment.

T1033
System Owner/User Discovery
GroupZIRCONIUM

ZIRCONIUM has used a tool to capture the username on a compromised host in order to register it with C2.

T1036
Masquerading
GroupZIRCONIUM

ZIRCONIUM has spoofed legitimate applications in phishing lures and changed file extensions to conceal installation of malware.

T1036.004
Masquerade Task or Service
GroupZIRCONIUM

ZIRCONIUM has created a run key named Dropbox Update Setup to mask a persistence mechanism for a malicious binary.

T1041
Exfiltration Over C2 Channel
GroupZIRCONIUM

ZIRCONIUM has exfiltrated files via the Dropbox API C2.

T1059.003
Windows Command Shell
GroupZIRCONIUM

ZIRCONIUM has used a tool to open a Windows Command Shell on a remote host.

T1059.006
Python
GroupZIRCONIUM

ZIRCONIUM has used Python-based implants to interact with compromised hosts.

T1082
System Information Discovery
GroupZIRCONIUM

ZIRCONIUM has used a tool to capture the processor architecture of a compromised host in order to register it with C2.

T1102.002
Bidirectional Communication
GroupZIRCONIUM

ZIRCONIUM has used Dropbox for C2 allowing upload and download of files as well as execution of arbitrary commands.

T1105
Ingress Tool Transfer
GroupZIRCONIUM

ZIRCONIUM has used tools to download malicious files to compromised hosts.

T1124
System Time Discovery
GroupZIRCONIUM

ZIRCONIUM has used a tool to capture the time on a compromised host in order to register it with C2.

T1204.001
Malicious Link
GroupZIRCONIUM

ZIRCONIUM has used malicious links in e-mails to lure victims into downloading malware.

T1218.007
Msiexec
GroupZIRCONIUM

ZIRCONIUM has used the msiexec.exe command-line utility to download and execute malicious MSI files.

T1547.001
Registry Run Keys / Startup Folder
GroupZIRCONIUM

ZIRCONIUM has created a Registry Run key named Dropbox Update Setup to establish persistence for a malicious Python binary.

T1555.003
Credentials from Web Browsers
GroupZIRCONIUM

ZIRCONIUM has used a tool to steal credentials from installed web browsers including Microsoft Internet Explorer and Google Chrome.

T1566.002
Spearphishing Link
GroupZIRCONIUM

ZIRCONIUM has used malicious links in e-mails to deliver malware.

T1567.002
Exfiltration to Cloud Storage
GroupZIRCONIUM

ZIRCONIUM has exfiltrated stolen data to Dropbox.

T1573.001
Symmetric Cryptography
GroupZIRCONIUM

ZIRCONIUM has used AES encrypted communications in C2.

T1583.006
Web Services
GroupZIRCONIUM

ZIRCONIUM has used GitHub to host malware linked in spearphishing e-mails.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.