ATT&CKReferencesMicrosoft - Customer Guidance on Recent Nation-State Cyber Attacks

Microsoft - Customer Guidance on Recent Nation-State Cyber Attacks

MSRC. (2020, December 13). Customer Guidance on Recent Nation-State Cyber Attacks. Retrieved December 30, 2020.

Open the source

Techniques1

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples4

TechniqueUsed byProcedure example
T1098.001
Additional Cloud Credentials
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 added credentials to OAuth Applications and Service Principals.

T1098.002
Additional Email Delegate Permissions
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 added their own devices as allowed IDs for active sync using `Set-CASMailbox`, allowing it to obtain copies of victim mailboxes. It also added additional permissions (such as Mail.Read and Mail.ReadWrite) to compromised Application or Service Principals.

T1218.011
Rundll32
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used `Rundll32.exe` to execute payloads.

T1606.002
SAML Tokens
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 created tokens using compromised SAML signing certificates.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.