ATT&CKReferencesCISA AA20-239A BeagleBoyz August 2020

CISA AA20-239A BeagleBoyz August 2020

DHS/CISA. (2020, August 26). FASTCash 2.0: North Korea's BeagleBoyz Robbing Banks. Retrieved September 29, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples25

TechniqueUsed byProcedure example
T1005
Data from Local System
GroupAPT38

APT38 has collected data from a compromised host.

T1033
System Owner/User Discovery
GroupAPT38

APT38 has identified primary users, currently logged in users, sets of users that commonly use a system, or inactive users.

T1053.003
Cron
GroupAPT38

APT38 has used cron to create pre-scheduled and periodic background jobs on a Linux system.

T1053.005
Scheduled Task
GroupAPT38

APT38 has used Task Scheduler to run programs at system startup or on a scheduled basis for persistence. Additionally, APT38 has used living-off-the-land scripts to execute a malicious script via a scheduled task.

T1059.001
PowerShell
GroupAPT38

APT38 has used PowerShell to execute commands and other operational tasks.

T1059.005
Visual Basic
GroupAPT38

APT38 has used VBScript to execute commands and other operational tasks.

T1070.004
File Deletion
GroupAPT38

APT38 has used a utility called CLOSESHAVE that can securely delete a file from the system. They have also removed malware, tools, or other non-native files used during the intrusion to reduce their footprint or as part of the post-intrusion cleanup process.

T1070.006
Timestomp
GroupAPT38

APT38 has modified data timestamps to mimic files that are in the same folder on a compromised host.

T1082
System Information Discovery
GroupAPT38

APT38 has attempted to get detailed information about a compromised host, including the operating system, version, patches, hotfixes, and service packs.

T1083
File and Directory Discovery
GroupAPT38

APT38 have enumerated files and directories, or searched in specific locations within a compromised host.

T1106
Native API
GroupAPT38

APT38 has used the Windows API to execute code within a victim's system.

T1110
Brute Force
GroupAPT38

APT38 has used brute force techniques to attempt account access when passwords are unknown or when password hashes are unavailable.

T1135
Network Share Discovery
GroupAPT38

APT38 has enumerated network shares on a compromised host.

T1189
Drive-by Compromise
GroupAPT38

APT38 has conducted watering holes schemes to gain initial access to victims.

T1204.002
Malicious File
GroupAPT38

APT38 has attempted to lure victims into enabling malicious macros within email attachments. Additionally, APT38 has used malicious Word documents and shortcut files.

T1217
Browser Information Discovery
GroupAPT38

APT38 has collected browser bookmark information to learn more about compromised hosts, obtain personal information about users, and acquire details about internal network resources.

T1218.011
Rundll32
GroupAPT38

APT38 has used rundll32.exe to execute binaries, scripts, and Control Panel Item files and to execute code via proxy to avoid triggering security tools.

T1505.003
Web Shell
GroupAPT38

APT38 has used web shells for persistence or to ensure redundant access.

T1518.001
Security Software Discovery
GroupAPT38

APT38 has identified security software, configurations, defensive tools, and sensors installed on a compromised system.

T1543.003
Windows Service
GroupAPT38

APT38 has installed a new Windows service to establish persistence.

T1566.001
Spearphishing Attachment
GroupAPT38

APT38 has conducted spearphishing campaigns using malicious email attachments.

T1569.002
Service Execution
GroupAPT38

APT38 has created new services or modified existing ones to run executables, commands, or scripts.

T1686
Disable or Modify System Firewall
GroupAPT38

APT38 have created firewall exemptions on specific ports, including ports 443, 6443, 8443, and 9443.

T1686.002
Network Device Firewall
GroupAPT38

APT38 have created firewall exemptions on specific ports, including ports 443, 6443, 8443, and 9443.

T1690
Prevent Command History Logging
GroupAPT38

APT38 has prepended a space to all of their terminal commands to operate without leaving traces in the HISTCONTROL environment.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.