DHS/CISA. (2020, August 26). FASTCash 2.0: North Korea's BeagleBoyz Robbing Banks. Retrieved September 29, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
GroupAPT38 | APT38 has collected data from a compromised host. |
| T1033 System Owner/User Discovery |
GroupAPT38 | APT38 has identified primary users, currently logged in users, sets of users that commonly use a system, or inactive users. |
| T1053.003 Cron |
GroupAPT38 | APT38 has used cron to create pre-scheduled and periodic background jobs on a Linux system. |
| T1053.005 Scheduled Task |
GroupAPT38 | APT38 has used Task Scheduler to run programs at system startup or on a scheduled basis for persistence. Additionally, APT38 has used living-off-the-land scripts to execute a malicious script via a scheduled task. |
| T1059.001 PowerShell |
GroupAPT38 | APT38 has used PowerShell to execute commands and other operational tasks. |
| T1059.005 Visual Basic |
GroupAPT38 | APT38 has used VBScript to execute commands and other operational tasks. |
| T1070.004 File Deletion |
GroupAPT38 | APT38 has used a utility called CLOSESHAVE that can securely delete a file from the system. They have also removed malware, tools, or other non-native files used during the intrusion to reduce their footprint or as part of the post-intrusion cleanup process. |
| T1070.006 Timestomp |
GroupAPT38 | APT38 has modified data timestamps to mimic files that are in the same folder on a compromised host. |
| T1082 System Information Discovery |
GroupAPT38 | APT38 has attempted to get detailed information about a compromised host, including the operating system, version, patches, hotfixes, and service packs. |
| T1083 File and Directory Discovery |
GroupAPT38 | APT38 have enumerated files and directories, or searched in specific locations within a compromised host. |
| T1106 Native API |
GroupAPT38 | APT38 has used the Windows API to execute code within a victim's system. |
| T1110 Brute Force |
GroupAPT38 | APT38 has used brute force techniques to attempt account access when passwords are unknown or when password hashes are unavailable. |
| T1135 Network Share Discovery |
GroupAPT38 | APT38 has enumerated network shares on a compromised host. |
| T1189 Drive-by Compromise |
GroupAPT38 | APT38 has conducted watering holes schemes to gain initial access to victims. |
| T1204.002 Malicious File |
GroupAPT38 | APT38 has attempted to lure victims into enabling malicious macros within email attachments. Additionally, APT38 has used malicious Word documents and shortcut files. |
| T1217 Browser Information Discovery |
GroupAPT38 | APT38 has collected browser bookmark information to learn more about compromised hosts, obtain personal information about users, and acquire details about internal network resources. |
| T1218.011 Rundll32 |
GroupAPT38 | APT38 has used rundll32.exe to execute binaries, scripts, and Control Panel Item files and to execute code via proxy to avoid triggering security tools. |
| T1505.003 Web Shell |
GroupAPT38 | APT38 has used web shells for persistence or to ensure redundant access. |
| T1518.001 Security Software Discovery |
GroupAPT38 | APT38 has identified security software, configurations, defensive tools, and sensors installed on a compromised system. |
| T1543.003 Windows Service |
GroupAPT38 | APT38 has installed a new Windows service to establish persistence. |
| T1566.001 Spearphishing Attachment |
GroupAPT38 | APT38 has conducted spearphishing campaigns using malicious email attachments. |
| T1569.002 Service Execution |
GroupAPT38 | APT38 has created new services or modified existing ones to run executables, commands, or scripts. |
| T1686 Disable or Modify System Firewall |
GroupAPT38 | APT38 have created firewall exemptions on specific ports, including ports 443, 6443, 8443, and 9443. |
| T1686.002 Network Device Firewall |
GroupAPT38 | APT38 have created firewall exemptions on specific ports, including ports 443, 6443, 8443, and 9443. |
| T1690 Prevent Command History Logging |
GroupAPT38 | APT38 has prepended a space to all of their terminal commands to operate without leaving traces in the HISTCONTROL environment. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.