ATT&CKReferencesUnit42 Agrius 2023

Unit42 Agrius 2023

Or Chechik, Tom Fakterman, Daniel Frank & Assaf Dahan. (2023, November 6). Agonizing Serpens (Aka Agrius) Targeting the Israeli Higher Education and Tech Sectors. Retrieved May 22, 2024.

Open the source

Techniques1

Groups0

None recorded.

Software2

Campaigns0

None recorded.

Procedure examples33

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupAgrius

Agrius used tools such as Mimikatz to dump LSASS memory to capture credentials in victim environments.

T1003.002
Security Account Manager
GroupAgrius

Agrius dumped the SAM file on victim machines to capture credentials.

T1005
Data from Local System
GroupAgrius

Agrius gathered data from database and other critical servers in victim environments, then used wiping mechanisms as an anti-analysis and anti-forensics mechanism.

T1018
Remote System Discovery
GroupAgrius

Agrius used the tool NBTscan to scan for remote, accessible hosts in victim environments.

T1021.001
Remote Desktop Protocol
GroupAgrius

Agrius tunnels RDP traffic through deployed web shells to access victim environments via compromised accounts. Agrius used the Plink tool to tunnel RDP connections for remote access and lateral movement in victim environments.

T1027.009
Embedded Payloads
MalwareMultiLayer Wiper

MultiLayer Wiper contains two binaries in its resources section, MultiList and MultiWip. MultiLayer Wiper drops and executes each of these items when run, then deletes them after execution.

T1036
Masquerading
GroupAgrius

Agrius used the Plink tool for tunneling and connections to remote machines, renaming it systems.exe in some instances.

T1041
Exfiltration Over C2 Channel
GroupAgrius

Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers.

T1046
Network Service Discovery
GroupAgrius

Agrius used the open-source port scanner WinEggDrop to perform detailed scans of hosts of interest in victim networks.

T1053.005
Scheduled Task
MalwareMultiLayer Wiper

MultiLayer Wiper creates a malicious scheduled task that launches a batch file to remove Windows Event Logs.

T1059.003
Windows Command Shell
MalwareMultiLayer Wiper

MultiLayer Wiper uses a batch script launched via a scheduled task to delete Windows Event Logs.

T1070
Indicator Removal
MalwareMultiLayer Wiper

MultiLayer Wiper uses a batch script to clear file system cache memory via the ProcessIdleTasks export in advapi32.dll as an anti-analysis and anti-forensics technique.

T1070.004
File Deletion
MalwareMultiLayer Wiper

MultiLayer Wiper uses a batch file, remover.bat to delete malware artifacts and the batch file itself during execution.

T1070.006
Timestomp
MalwareMultiLayer Wiper

MultiLayer Wiper changes timestamps of overwritten files to either 1601.1.1 for NTFS filesystems, or 1980.1.1 for all other filesystems.

T1074.001
Local Data Staging
GroupAgrius

Agrius has used the folder, C:\\windows\\temp\\s\\, to stage data for exfiltration.

T1078.002
Domain Accounts
GroupAgrius

Agrius attempted to acquire valid credentials for victim environments through various means to enable follow-on lateral movement.

T1083
File and Directory Discovery
MalwareMultiLayer Wiper

MultiLayer Wiper generates a list of all files and paths on the fixed drives of an infected system, enumerating all files on the system except specific folders defined in a hardcoded list.

T1110
Brute Force
GroupAgrius

Agrius engaged in various brute forcing activities via SMB in victim environments.

T1110.003
Password Spraying
GroupAgrius

Agrius engaged in password spraying via SMB in victim environments.

T1119
Automated Collection
GroupAgrius

Agrius used a custom tool, sql.net4.exe, to query SQL databases and then identify and extract personally identifiable information.

T1485
Data Destruction
MalwareMultiLayer Wiper

MultiLayer Wiper deletes files on network drives, but corrupts and overwrites with random data files stored locally.

T1490
Inhibit System Recovery
MalwareMultiLayer Wiper

MultiLayer Wiper wipes the boot sector of infected systems to inhibit system recovery.

T1490
Inhibit System Recovery
MalwareBFG Agonizer

BFG Agonizer wipes the boot sector of infected machines to inhibit system recovery.

T1529
System Shutdown/Reboot
MalwareMultiLayer Wiper

MultiLayer Wiper reboots the infected system following wiping and related tasks to prevent system recovery.

T1529
System Shutdown/Reboot
MalwareBFG Agonizer

BFG Agonizer uses elevated privileges to call NtRaiseHardError to induce a "blue screen of death" on infected systems, causing a system crash. Once shut down, the system is no longer bootable.

T1554
Compromise Host Software Binary
MalwareBFG Agonizer

BFG Agonizer uses DLL unhooking to remove user mode inline hooks that security solutions often implement. BFG Agonizer also uses IAT unhooking to remove user-mode IAT hooks that security solutions also use.

T1560.001
Archive via Utility
GroupAgrius

Agrius used 7zip to archive extracted data in preparation for exfiltration.

T1561.002
Disk Structure Wipe
MalwareBFG Agonizer

BFG Agonizer retrieves a device handle to \\\\.\\PhysicalDrive0 to wipe the boot sector of a given disk.

T1561.002
Disk Structure Wipe
MalwareMultiLayer Wiper

MultiLayer Wiper opens a handle to \\\\\\\\.\\\\PhysicalDrive0 and wipes the first 512 bytes of data from this location, removing the boot sector.

T1565.001
Stored Data Manipulation
MalwareMultiLayer Wiper

MultiLayer Wiper changes the original path information of deleted files to make recovery efforts more difficult.

T1685
Disable or Modify Tools
GroupAgrius

Agrius used several mechanisms to try to disable security tools. Agrius attempted to modify EDR-related services to disable auto-start on system reboot. Agrius used a publicly available driver, GMER64.sys typically used for anti-rootkit functionality, to selectively stop and remove security software processes.

T1685
Disable or Modify Tools
MalwareMultiLayer Wiper

MultiLayer Wiper removes the Volume Shadow Copy (VSS) service from infected devices along with all present shadow copies.

T1685.005
Clear Windows Event Logs
MalwareMultiLayer Wiper

MultiLayer Wiper removes Windows event logs during execution.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.