ATT&CKReferencesCybereason Soft Cell June 2019

Cybereason Soft Cell June 2019

Cybereason Nocturnus. (2019, June 25). Operation Soft Cell: A Worldwide Campaign Against Telecommunications Providers. Retrieved July 18, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples27

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupGALLIUM

GALLIUM used a modified version of Mimikatz along with a PowerShell-based Mimikatz to dump credentials on the victim machines.

T1003.002
Security Account Manager
GroupGALLIUM

GALLIUM used reg commands to dump specific hives from the Windows Registry, such as the SAM hive, and obtain password hashes.

T1005
Data from Local System
GroupGALLIUM

GALLIUM collected data from the victim's local system, including password hashes from the SAM hive in the Registry.

T1016
System Network Configuration Discovery
GroupGALLIUM

GALLIUM used ipconfig /all to obtain information about the victim network configuration. The group also ran a modified version of NBTscan to identify available NetBIOS name servers.

T1018
Remote System Discovery
GroupGALLIUM

GALLIUM used a modified version of NBTscan to identify available NetBIOS name servers over the network as well as ping to identify remote systems.

T1027
Obfuscated Files or Information
GroupGALLIUM

GALLIUM used a modified version of HTRAN in which they obfuscated strings such as debug messages in an apparent attempt to evade detection.

T1027.002
Software Packing
GroupGALLIUM

GALLIUM packed some payloads using different types of packers, both known and custom.

T1027.005
Indicator Removal from Tools
GroupGALLIUM

GALLIUM ensured each payload had a unique hash, including by using different types of packers.

T1033
System Owner/User Discovery
GroupGALLIUM

GALLIUM used whoami and query user to obtain information about the victim user.

T1036.003
Rename Legitimate Utilities
GroupGALLIUM

GALLIUM used a renamed cmd.exe file to evade detection.

T1041
Exfiltration Over C2 Channel
GroupGALLIUM

GALLIUM used Web shells and HTRAN for C2 and to exfiltrate data.

T1047
Windows Management Instrumentation
GroupGALLIUM

GALLIUM used WMI for execution to assist in lateral movement as well as for installing tools across multiple assets.

T1049
System Network Connections Discovery
GroupGALLIUM

GALLIUM used netstat -oan to obtain information about the victim network connections.

T1053.005
Scheduled Task
GroupGALLIUM

GALLIUM established persistence for PoisonIvy by created a scheduled task.

T1059.001
PowerShell
GroupGALLIUM

GALLIUM used PowerShell for execution to assist in lateral movement as well as for dumping credentials stored on compromised machines.

T1059.003
Windows Command Shell
GroupGALLIUM

GALLIUM used the Windows command shell to execute commands.

T1074.001
Local Data Staging
GroupGALLIUM

GALLIUM compressed and staged files in multi-part archives in the Recycle Bin prior to exfiltration.

T1078
Valid Accounts
GroupGALLIUM

GALLIUM leveraged valid accounts to maintain access to a victim network.

T1090.002
External Proxy
GroupGALLIUM

GALLIUM used a modified version of HTRAN to redirect connections between networks.

T1105
Ingress Tool Transfer
GroupGALLIUM

GALLIUM dropped additional tools to victims during their operation, including portqry.exe, a renamed cmd.exe file, winrar, and HTRAN.

T1133
External Remote Services
GroupGALLIUM

GALLIUM has used VPN services, including SoftEther VPN, to access and maintain persistence in victim environments.

T1136.002
Domain Account
GroupGALLIUM

GALLIUM created high-privileged domain user accounts to maintain access to victim networks.

T1190
Exploit Public-Facing Application
GroupGALLIUM

GALLIUM exploited a publicly-facing servers including Wildfly/JBoss servers to gain access to the network.

T1505.003
Web Shell
GroupGALLIUM

GALLIUM used Web shells to persist in victim environments and assist in execution and exfiltration.

T1550.002
Pass the Hash
GroupGALLIUM

GALLIUM used dumped hashes to authenticate to other machines via pass the hash.

T1560.001
Archive via Utility
GroupGALLIUM

GALLIUM used WinRAR to compress and encrypt stolen data prior to exfiltration.

T1574.001
DLL
GroupGALLIUM

GALLIUM used DLL side-loading to covertly load PoisonIvy into memory on the victim machine.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.