ATT&CKReferencesBitdefender StrongPity June 2020

Bitdefender StrongPity June 2020

Tudorica, R. et al. (2020, June 30). StrongPity APT - Revealing Trojanized Tools, Working Hours and Infrastructure. Retrieved July 20, 2020.

Open the source

Techniques1

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples23

TechniqueUsed byProcedure example
T1020
Automated Exfiltration
MalwareStrongPity

StrongPity can automatically exfiltrate collected documents to the C2 server.

T1027.013
Encrypted/Encoded File
MalwareStrongPity

StrongPity has used encrypted strings in its dropper component.

T1036.004
Masquerade Task or Service
GroupPROMETHIUM

PROMETHIUM has named services to appear legitimate.

T1036.004
Masquerade Task or Service
MalwareStrongPity

StrongPity has named services to appear legitimate.

T1036.005
Match Legitimate Resource Name or Location
GroupPROMETHIUM

PROMETHIUM has disguised malicious installer files by bundling them with legitimate software installers.

T1041
Exfiltration Over C2 Channel
MalwareStrongPity

StrongPity can exfiltrate collected documents through C2 channels.

T1070.004
File Deletion
MalwareStrongPity

StrongPity can delete previously exfiltrated files from the compromised host.

T1071.001
Web Protocols
MalwareStrongPity

StrongPity can use HTTP and HTTPS in C2 communications.

T1078.003
Local Accounts
GroupPROMETHIUM

PROMETHIUM has created admin accounts on a compromised host.

T1090.003
Multi-hop Proxy
MalwareStrongPity

StrongPity can use multiple layers of proxy servers to hide terminal nodes in its infrastructure.

T1105
Ingress Tool Transfer
MalwareStrongPity

StrongPity can download files to specified targets.

T1119
Automated Collection
MalwareStrongPity

StrongPity has a file searcher component that can automatically collect and archive files based on a predefined list of file extensions.

T1189
Drive-by Compromise
GroupPROMETHIUM

PROMETHIUM has used watering hole attacks to deliver malicious versions of legitimate installers.

T1204.002
Malicious File
MalwareStrongPity

StrongPity has been executed via compromised installation files for legitimate software including compression applications, security software, browsers, file recovery applications, and other tools and utilities.

T1204.002
Malicious File
GroupPROMETHIUM

PROMETHIUM has attempted to get users to execute compromised installation files for legitimate software including compression applications, security software, browsers, file recovery applications, and other tools and utilities.

T1205.001
Port Knocking
GroupPROMETHIUM

PROMETHIUM has used a script that configures the knockd service and firewall to only accept C2 connections from systems that use a specified sequence of knock ports.

T1543.003
Windows Service
GroupPROMETHIUM

PROMETHIUM has created new services and modified existing services for persistence.

T1553.002
Code Signing
MalwareStrongPity

StrongPity has been signed with self-signed certificates.

T1553.002
Code Signing
GroupPROMETHIUM

PROMETHIUM has signed code with self-signed certificates.

T1560.003
Archive via Custom Method
MalwareStrongPity

StrongPity can compress and encrypt archived files into multiple .sft files with a repeated xor encryption scheme.

T1569.002
Service Execution
MalwareStrongPity

StrongPity can install a service to execute itself as a service.

T1571
Non-Standard Port
MalwareStrongPity

StrongPity has used HTTPS over port 1402 in C2 communication.

T1587.002
Code Signing Certificates
GroupPROMETHIUM

PROMETHIUM has created self-signed certificates to sign malicious installers.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.