Chen, J., et al. (2022). Delving Deep: An Analysis of Earth Lusca’s Operations. Retrieved July 1, 2022.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupEarth Lusca | Earth Lusca has used ProcDump to obtain the hashes of credentials by dumping the memory of the LSASS process. |
| T1003.006 DCSync |
GroupEarth Lusca | Earth Lusca has used a |
| T1007 System Service Discovery |
GroupEarth Lusca | Earth Lusca has used Tasklist to obtain information from a compromised host. |
| T1016 System Network Configuration Discovery |
GroupEarth Lusca | Earth Lusca used the command |
| T1018 Remote System Discovery |
GroupEarth Lusca | Earth Lusca used the command |
| T1027 Obfuscated Files or Information |
GroupEarth Lusca | Earth Lusca used Base64 to encode strings. |
| T1027 Obfuscated Files or Information |
MalwareShadowPad | ShadowPad has encrypted its payload, a virtual file system, and various files. |
| T1027.003 Steganography |
GroupEarth Lusca | Earth Lusca has used steganography to hide shellcode in a BMP image file. |
| T1027.011 Fileless Storage |
MalwareShadowPad | ShadowPad maintains a configuration block and virtual file system in the Registry. |
| T1033 System Owner/User Discovery |
GroupEarth Lusca | Earth Lusca collected information on user accounts via the |
| T1036.005 Match Legitimate Resource Name or Location |
GroupEarth Lusca | Earth Lusca used the command `move [file path] c:\windows\system32\spool\prtprocs\x64\spool.dll` to move and register a malicious DLL name as a Windows print processor, which eventually was loaded by the Print Spooler service. |
| T1047 Windows Management Instrumentation |
GroupEarth Lusca | Earth Lusca used a VBA script to execute WMI. |
| T1049 System Network Connections Discovery |
GroupEarth Lusca | Earth Lusca employed a PowerShell script called RDPConnectionParser to read and filter the Windows event log “Microsoft-Windows-TerminalServices-RDPClient/Operational” |
| T1053.005 Scheduled Task |
GroupEarth Lusca | Earth Lusca used the command |
| T1057 Process Discovery |
GroupEarth Lusca | Earth Lusca has used Tasklist to obtain information from a compromised host. |
| T1059.001 PowerShell |
GroupEarth Lusca | Earth Lusca has used PowerShell to execute commands. |
| T1059.005 Visual Basic |
GroupEarth Lusca | Earth Lusca used VBA scripts. |
| T1059.006 Python |
GroupEarth Lusca | Earth Lusca used Python scripts for port scanning or building reverse shells. |
| T1059.007 JavaScript |
GroupEarth Lusca | Earth Lusca has manipulated legitimate websites to inject malicious JavaScript code as part of their watering hole operations. |
| T1090 Proxy |
GroupEarth Lusca | Earth Lusca adopted Cloudflare as a proxy for compromised servers. |
| T1098.004 SSH Authorized Keys |
GroupEarth Lusca | Earth Lusca has dropped an SSH-authorized key in the `/root/.ssh` folder in order to access a compromised server with SSH. |
| T1112 Modify Registry |
GroupEarth Lusca | Earth Lusca modified the registry using the command |
| T1112 Modify Registry |
MalwareShadowPad | ShadowPad can modify the Registry to store and maintain a configuration block and virtual file system. |
| T1140 Deobfuscate/Decode Files or Information |
GroupEarth Lusca | Earth Lusca has used certutil to decode a string into a cabinet file. |
| T1189 Drive-by Compromise |
GroupEarth Lusca | Earth Lusca has performed watering hole attacks. |
| T1190 Exploit Public-Facing Application |
GroupEarth Lusca | Earth Lusca has compromised victims by directly exploiting vulnerabilities of public-facing servers, including those associated with Microsoft Exchange and Oracle GlassFish. |
| T1204.001 Malicious Link |
GroupEarth Lusca | Earth Lusca has sent spearphishing emails that required the user to click on a malicious link and subsequently open a decoy document with a malicious loader. |
| T1204.002 Malicious File |
GroupEarth Lusca | Earth Lusca required users to click on a malicious file for the loader to activate. |
| T1210 Exploitation of Remote Services |
GroupEarth Lusca | Earth Lusca has used Mimikatz to exploit a domain controller via the ZeroLogon exploit (CVE-2020-1472). |
| T1218.005 Mshta |
GroupEarth Lusca | Earth Lusca has used `mshta.exe` to load an HTA script within a malicious .LNK file. |
| T1482 Domain Trust Discovery |
GroupEarth Lusca | Earth Lusca has used Nltest to obtain information about domain controllers. |
| T1543.003 Windows Service |
GroupEarth Lusca | Earth Lusca created a service using the command |
| T1547.012 Print Processors |
GroupEarth Lusca | Earth Lusca has added the Registry key `HKLM\SYSTEM\ControlSet001\Control\Print\Environments\Windows x64\Print Processors\UDPrint” /v Driver /d “spool.dll /f` to load malware as a Print Processor. |
| T1548.002 Bypass User Account Control |
GroupEarth Lusca | Earth Lusca has used the Fodhelper UAC bypass technique to gain elevated privileges. |
| T1560.001 Archive via Utility |
GroupEarth Lusca | Earth Lusca has used WinRAR to compress stolen files into an archive prior to exfiltration. |
| T1566.002 Spearphishing Link |
GroupEarth Lusca | Earth Lusca has sent spearphishing emails to potential targets that contained a malicious link. |
| T1567.002 Exfiltration to Cloud Storage |
GroupEarth Lusca | Earth Lusca has used the megacmd tool to upload stolen files from a victim network to MEGA. |
| T1574.001 DLL |
GroupEarth Lusca | Earth Lusca has placed a malicious payload in `%WINDIR%\SYSTEM32\oci.dll` so it would be sideloaded by the MSDTC service. |
| T1583.001 Domains |
GroupEarth Lusca | Earth Lusca has registered domains, intended to look like legitimate target domains, that have been used in watering hole attacks. |
| T1583.004 Server |
GroupEarth Lusca | Earth Lusca has acquired multiple servers for some of their operations, using each server for a different role. |
| T1583.006 Web Services |
GroupEarth Lusca | Earth Lusca has established GitHub accounts to host their malware. |
| T1584.004 Server |
GroupEarth Lusca | Earth Lusca has used compromised web servers as part of their operational infrastructure. |
| T1584.006 Web Services |
GroupEarth Lusca | Earth Lusca has compromised Google Drive repositories. |
| T1588.001 Malware |
GroupEarth Lusca | Earth Lusca has acquired and used a variety of malware, including Cobalt Strike. |
| T1588.002 Tool |
GroupEarth Lusca | Earth Lusca has acquired and used a variety of open source tools. |
| T1595.002 Vulnerability Scanning |
GroupEarth Lusca | Earth Lusca has scanned for vulnerabilities in the public-facing servers of their targets. |
| T1608.001 Upload Malware |
GroupEarth Lusca | Earth Lusca has staged malware and malicious files on compromised web servers, GitHub, and Google Drive. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.