ATT&CKReferencesRedCanary Mockingbird May 2020

RedCanary Mockingbird May 2020

Lambert, T. (2020, May 7). Introducing Blue Mockingbird. Retrieved May 26, 2020.

Open the source

Techniques1

Groups1

Software1

Campaigns0

None recorded.

Procedure examples22

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupBlue Mockingbird

Blue Mockingbird has used Mimikatz to retrieve credentials from LSASS memory.

T1021.001
Remote Desktop Protocol
GroupBlue Mockingbird

Blue Mockingbird has used Remote Desktop to log on to servers interactively and manually copy files to remote hosts.

T1021.002
SMB/Windows Admin Shares
GroupBlue Mockingbird

Blue Mockingbird has used Windows Explorer to manually copy malicious files to remote hosts over SMB.

T1027.013
Encrypted/Encoded File
GroupBlue Mockingbird

Blue Mockingbird has obfuscated the wallet address in the payload binary.

T1036.005
Match Legitimate Resource Name or Location
GroupBlue Mockingbird

Blue Mockingbird has masqueraded their XMRIG payload name by naming it wercplsupporte.dll after the legitimate wercplsupport.dll file.

T1047
Windows Management Instrumentation
GroupBlue Mockingbird

Blue Mockingbird has used wmic.exe to set environment variables.

T1053.005
Scheduled Task
GroupBlue Mockingbird

Blue Mockingbird has used Windows Scheduled Tasks to establish persistence on local and remote hosts.

T1059.001
PowerShell
GroupBlue Mockingbird

Blue Mockingbird has used PowerShell reverse TCP shells to issue interactive commands over a network connection.

T1059.003
Windows Command Shell
GroupBlue Mockingbird

Blue Mockingbird has used batch script files to automate execution and deployment of payloads.

T1082
System Information Discovery
GroupBlue Mockingbird

Blue Mockingbird has collected hardware details for the victim's system, including CPU and memory information.

T1090
Proxy
GroupBlue Mockingbird

Blue Mockingbird has used FRP, ssf, and Venom to establish SOCKS proxy connections.

T1112
Modify Registry
GroupBlue Mockingbird

Blue Mockingbird has used Windows Registry modifications to specify a DLL payload.

T1134
Access Token Manipulation
GroupBlue Mockingbird

Blue Mockingbird has used JuicyPotato to abuse the SeImpersonate token privilege to escalate from web application pool accounts to NT Authority\SYSTEM.

T1190
Exploit Public-Facing Application
GroupBlue Mockingbird

Blue Mockingbird has gained initial access by exploiting CVE-2019-18935, a vulnerability within Telerik UI for ASP.NET AJAX.

T1218.010
Regsvr32
GroupBlue Mockingbird

Blue Mockingbird has executed custom-compiled XMRIG miner DLLs using regsvr32.exe.

T1218.011
Rundll32
GroupBlue Mockingbird

Blue Mockingbird has executed custom-compiled XMRIG miner DLLs using rundll32.exe.

T1496.001
Compute Hijacking
GroupBlue Mockingbird

Blue Mockingbird has used XMRIG to mine cryptocurrency on victim systems.

T1543.003
Windows Service
GroupBlue Mockingbird

Blue Mockingbird has made their XMRIG payloads persistent as a Windows Service.

T1546.003
Windows Management Instrumentation Event Subscription
GroupBlue Mockingbird

Blue Mockingbird has used mofcomp.exe to establish WMI Event Subscription persistence mechanisms configured from a *.mof file.

T1569.002
Service Execution
GroupBlue Mockingbird

Blue Mockingbird has executed custom-compiled XMRIG miner DLLs by configuring them to execute via the "wercplsupport" service.

T1574.012
COR_PROFILER
GroupBlue Mockingbird

Blue Mockingbird has used wmic.exe and Windows Registry modifications to set the COR_PROFILER environment variable to execute a malicious DLL whenever a process loads the .NET CLR.

T1588.002
Tool
GroupBlue Mockingbird

Blue Mockingbird has obtained and used tools such as Mimikatz.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.