ATT&CKReferencesFireEye APT17

FireEye APT17

FireEye Labs/FireEye Threat Intelligence. (2015, May 14). Hiding in Plain Sight: FireEye and Microsoft Expose Obfuscation Tactic. Retrieved November 17, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples9

TechniqueUsed byProcedure example
T1057
Process Discovery
MalwareBLACKCOFFEE

BLACKCOFFEE has the capability to discover processes.

T1059.003
Windows Command Shell
MalwareBLACKCOFFEE

BLACKCOFFEE has the capability to create a reverse shell.

T1070.004
File Deletion
MalwareBLACKCOFFEE

BLACKCOFFEE has the capability to delete files.

T1083
File and Directory Discovery
MalwareBLACKCOFFEE

BLACKCOFFEE has the capability to enumerate files.

T1102.001
Dead Drop Resolver
MalwareBLACKCOFFEE

BLACKCOFFEE uses Microsoft’s TechNet Web portal to obtain a dead drop resolver containing an encoded tag with the IP address of a command and control server.

T1102.002
Bidirectional Communication
MalwareBLACKCOFFEE

BLACKCOFFEE has also obfuscated its C2 traffic as normal traffic to sites such as Github.

T1104
Multi-Stage Channels
MalwareBLACKCOFFEE

BLACKCOFFEE uses Microsoft’s TechNet Web portal to obtain an encoded tag containing the IP address of a command and control server and then communicates separately with that IP address for C2. If the C2 server is discovered or shut down, the threat actors can update the encoded IP address on TechNet to maintain control of the victims’ machines.

T1583.006
Web Services
GroupAPT17

APT17 has created profile pages in Microsoft TechNet that were used as C2 infrastructure.

T1585
Establish Accounts
GroupAPT17

APT17 has created and cultivated profile pages in Microsoft TechNet. To make profile pages appear more legitimate, APT17 has created biographical sections and posted in forum threads.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.