Tudorica, R. et al. (2020, June 30). StrongPity APT - Revealing Trojanized Tools, Working Hours and Infrastructure. Retrieved July 20, 2020.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1020 Automated Exfiltration |
MalwareStrongPity | StrongPity can automatically exfiltrate collected documents to the C2 server. |
| T1027.013 Encrypted/Encoded File |
MalwareStrongPity | StrongPity has used encrypted strings in its dropper component. |
| T1036.004 Masquerade Task or Service |
GroupPROMETHIUM | PROMETHIUM has named services to appear legitimate. |
| T1036.004 Masquerade Task or Service |
MalwareStrongPity | StrongPity has named services to appear legitimate. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupPROMETHIUM | PROMETHIUM has disguised malicious installer files by bundling them with legitimate software installers. |
| T1041 Exfiltration Over C2 Channel |
MalwareStrongPity | StrongPity can exfiltrate collected documents through C2 channels. |
| T1070.004 File Deletion |
MalwareStrongPity | StrongPity can delete previously exfiltrated files from the compromised host. |
| T1071.001 Web Protocols |
MalwareStrongPity | StrongPity can use HTTP and HTTPS in C2 communications. |
| T1078.003 Local Accounts |
GroupPROMETHIUM | PROMETHIUM has created admin accounts on a compromised host. |
| T1090.003 Multi-hop Proxy |
MalwareStrongPity | StrongPity can use multiple layers of proxy servers to hide terminal nodes in its infrastructure. |
| T1105 Ingress Tool Transfer |
MalwareStrongPity | StrongPity can download files to specified targets. |
| T1119 Automated Collection |
MalwareStrongPity | StrongPity has a file searcher component that can automatically collect and archive files based on a predefined list of file extensions. |
| T1189 Drive-by Compromise |
GroupPROMETHIUM | PROMETHIUM has used watering hole attacks to deliver malicious versions of legitimate installers. |
| T1204.002 Malicious File |
MalwareStrongPity | StrongPity has been executed via compromised installation files for legitimate software including compression applications, security software, browsers, file recovery applications, and other tools and utilities. |
| T1204.002 Malicious File |
GroupPROMETHIUM | PROMETHIUM has attempted to get users to execute compromised installation files for legitimate software including compression applications, security software, browsers, file recovery applications, and other tools and utilities. |
| T1205.001 Port Knocking |
GroupPROMETHIUM | PROMETHIUM has used a script that configures the knockd service and firewall to only accept C2 connections from systems that use a specified sequence of knock ports. |
| T1543.003 Windows Service |
GroupPROMETHIUM | PROMETHIUM has created new services and modified existing services for persistence. |
| T1553.002 Code Signing |
MalwareStrongPity | StrongPity has been signed with self-signed certificates. |
| T1553.002 Code Signing |
GroupPROMETHIUM | PROMETHIUM has signed code with self-signed certificates. |
| T1560.003 Archive via Custom Method |
MalwareStrongPity | StrongPity can compress and encrypt archived files into multiple .sft files with a repeated xor encryption scheme. |
| T1569.002 Service Execution |
MalwareStrongPity | StrongPity can install a service to execute itself as a service. |
| T1571 Non-Standard Port |
MalwareStrongPity | StrongPity has used HTTPS over port 1402 in C2 communication. |
| T1587.002 Code Signing Certificates |
GroupPROMETHIUM | PROMETHIUM has created self-signed certificates to sign malicious installers. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.