MSTIC. (2019, December 12). GALLIUM: Targeting global telecom. Retrieved January 13, 2021.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupGALLIUM | GALLIUM used a modified version of Mimikatz along with a PowerShell-based Mimikatz to dump credentials on the victim machines. |
| T1005 Data from Local System |
MalwareBlackMould | BlackMould can copy files on a compromised host. |
| T1059.003 Windows Command Shell |
MalwareBlackMould | BlackMould can run cmd.exe with parameters. |
| T1071.001 Web Protocols |
MalwareBlackMould | BlackMould can send commands to C2 in the body of HTTP POST requests. |
| T1083 File and Directory Discovery |
MalwareBlackMould | BlackMould has the ability to find files on the targeted system. |
| T1105 Ingress Tool Transfer |
GroupGALLIUM | GALLIUM dropped additional tools to victims during their operation, including portqry.exe, a renamed cmd.exe file, winrar, and HTRAN. |
| T1105 Ingress Tool Transfer |
MalwareBlackMould | BlackMould has the ability to download files to the victim's machine. |
| T1133 External Remote Services |
GroupGALLIUM | GALLIUM has used VPN services, including SoftEther VPN, to access and maintain persistence in victim environments. |
| T1136.002 Domain Account |
GroupGALLIUM | GALLIUM created high-privileged domain user accounts to maintain access to victim networks. |
| T1190 Exploit Public-Facing Application |
GroupGALLIUM | GALLIUM exploited a publicly-facing servers including Wildfly/JBoss servers to gain access to the network. |
| T1505.003 Web Shell |
GroupGALLIUM | GALLIUM used Web shells to persist in victim environments and assist in execution and exfiltration. |
| T1553.002 Code Signing |
GroupGALLIUM | GALLIUM has used stolen certificates to sign its tools including those from Whizzimo LLC. |
| T1560.001 Archive via Utility |
GroupGALLIUM | GALLIUM used WinRAR to compress and encrypt stolen data prior to exfiltration. |
| T1570 Lateral Tool Transfer |
GroupGALLIUM | GALLIUM has used PsExec to move laterally between hosts in the target network. |
| T1583.004 Server |
GroupGALLIUM | GALLIUM has used Taiwan-based servers that appear to be exclusive to GALLIUM. |
| T1588.002 Tool |
GroupGALLIUM | GALLIUM has used a variety of widely-available tools, which in some cases they modified to add functionality and/or subvert antimalware solutions. |
| T1680 Local Storage Discovery |
MalwareBlackMould | BlackMould can enumerate local drives on a compromised host. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.