Or Chechik, Tom Fakterman, Daniel Frank & Assaf Dahan. (2023, November 6). Agonizing Serpens (Aka Agrius) Targeting the Israeli Higher Education and Tech Sectors. Retrieved May 22, 2024.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupAgrius | Agrius used tools such as Mimikatz to dump LSASS memory to capture credentials in victim environments. |
| T1003.002 Security Account Manager |
GroupAgrius | Agrius dumped the SAM file on victim machines to capture credentials. |
| T1005 Data from Local System |
GroupAgrius | Agrius gathered data from database and other critical servers in victim environments, then used wiping mechanisms as an anti-analysis and anti-forensics mechanism. |
| T1018 Remote System Discovery |
GroupAgrius | Agrius used the tool NBTscan to scan for remote, accessible hosts in victim environments. |
| T1021.001 Remote Desktop Protocol |
GroupAgrius | Agrius tunnels RDP traffic through deployed web shells to access victim environments via compromised accounts. Agrius used the Plink tool to tunnel RDP connections for remote access and lateral movement in victim environments. |
| T1027.009 Embedded Payloads |
MalwareMultiLayer Wiper | MultiLayer Wiper contains two binaries in its resources section, MultiList and MultiWip. MultiLayer Wiper drops and executes each of these items when run, then deletes them after execution. |
| T1036 Masquerading |
GroupAgrius | Agrius used the Plink tool for tunneling and connections to remote machines, renaming it |
| T1041 Exfiltration Over C2 Channel |
GroupAgrius | Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers. |
| T1046 Network Service Discovery |
GroupAgrius | Agrius used the open-source port scanner |
| T1053.005 Scheduled Task |
MalwareMultiLayer Wiper | MultiLayer Wiper creates a malicious scheduled task that launches a batch file to remove Windows Event Logs. |
| T1059.003 Windows Command Shell |
MalwareMultiLayer Wiper | MultiLayer Wiper uses a batch script launched via a scheduled task to delete Windows Event Logs. |
| T1070 Indicator Removal |
MalwareMultiLayer Wiper | MultiLayer Wiper uses a batch script to clear file system cache memory via the |
| T1070.004 File Deletion |
MalwareMultiLayer Wiper | MultiLayer Wiper uses a batch file, |
| T1070.006 Timestomp |
MalwareMultiLayer Wiper | MultiLayer Wiper changes timestamps of overwritten files to either 1601.1.1 for NTFS filesystems, or 1980.1.1 for all other filesystems. |
| T1074.001 Local Data Staging |
GroupAgrius | Agrius has used the folder, |
| T1078.002 Domain Accounts |
GroupAgrius | Agrius attempted to acquire valid credentials for victim environments through various means to enable follow-on lateral movement. |
| T1083 File and Directory Discovery |
MalwareMultiLayer Wiper | MultiLayer Wiper generates a list of all files and paths on the fixed drives of an infected system, enumerating all files on the system except specific folders defined in a hardcoded list. |
| T1110 Brute Force |
GroupAgrius | Agrius engaged in various brute forcing activities via SMB in victim environments. |
| T1110.003 Password Spraying |
GroupAgrius | Agrius engaged in password spraying via SMB in victim environments. |
| T1119 Automated Collection |
GroupAgrius | Agrius used a custom tool, |
| T1485 Data Destruction |
MalwareMultiLayer Wiper | MultiLayer Wiper deletes files on network drives, but corrupts and overwrites with random data files stored locally. |
| T1490 Inhibit System Recovery |
MalwareMultiLayer Wiper | MultiLayer Wiper wipes the boot sector of infected systems to inhibit system recovery. |
| T1490 Inhibit System Recovery |
MalwareBFG Agonizer | BFG Agonizer wipes the boot sector of infected machines to inhibit system recovery. |
| T1529 System Shutdown/Reboot |
MalwareMultiLayer Wiper | MultiLayer Wiper reboots the infected system following wiping and related tasks to prevent system recovery. |
| T1529 System Shutdown/Reboot |
MalwareBFG Agonizer | BFG Agonizer uses elevated privileges to call |
| T1554 Compromise Host Software Binary |
MalwareBFG Agonizer | BFG Agonizer uses DLL unhooking to remove user mode inline hooks that security solutions often implement. BFG Agonizer also uses IAT unhooking to remove user-mode IAT hooks that security solutions also use. |
| T1560.001 Archive via Utility |
GroupAgrius | Agrius used 7zip to archive extracted data in preparation for exfiltration. |
| T1561.002 Disk Structure Wipe |
MalwareBFG Agonizer | BFG Agonizer retrieves a device handle to |
| T1561.002 Disk Structure Wipe |
MalwareMultiLayer Wiper | MultiLayer Wiper opens a handle to |
| T1565.001 Stored Data Manipulation |
MalwareMultiLayer Wiper | MultiLayer Wiper changes the original path information of deleted files to make recovery efforts more difficult. |
| T1685 Disable or Modify Tools |
GroupAgrius | Agrius used several mechanisms to try to disable security tools. Agrius attempted to modify EDR-related services to disable auto-start on system reboot. Agrius used a publicly available driver, |
| T1685 Disable or Modify Tools |
MalwareMultiLayer Wiper | MultiLayer Wiper removes the Volume Shadow Copy (VSS) service from infected devices along with all present shadow copies. |
| T1685.005 Clear Windows Event Logs |
MalwareMultiLayer Wiper | MultiLayer Wiper removes Windows event logs during execution. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.