ATT&CKReferencesFireEye Operation Double Tap

FireEye Operation Double Tap

Moran, N., et al. (2014, November 21). Operation Double Tap. Retrieved January 14, 2016.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples10

TechniqueUsed byProcedure example
T1033
System Owner/User Discovery
GroupAPT3

An APT3 downloader uses the Windows command "cmd.exe" /C whoami to verify that it is running with the elevated privileges of “System.”

T1053.005
Scheduled Task
GroupAPT3

An APT3 downloader creates persistence by creating the following scheduled task: schtasks /create /tn "mysc" /tr C:\Users\Public\test.exe /sc ONLOGON /ru "System".

T1059.001
PowerShell
GroupAPT3

APT3 has used PowerShell on victim systems to download and run payloads after exploitation.

T1059.003
Windows Command Shell
GroupAPT3

An APT3 downloader uses the Windows command "cmd.exe" /C whoami. The group also uses a tool to execute commands on remote computers.

T1090.002
External Proxy
GroupAPT3

An APT3 downloader establishes SOCKS5 connections for its initial C2.

T1095
Non-Application Layer Protocol
GroupAPT3

An APT3 downloader establishes SOCKS5 connections for its initial C2.

T1104
Multi-Stage Channels
GroupAPT3

An APT3 downloader first establishes a SOCKS5 connection to 192.157.198[.]103 using TCP port 1913; once the server response is verified, it then requests a connection to 192.184.60[.]229 on TCP port 81.

T1543.003
Windows Service
GroupAPT3

APT3 has a tool that creates a new service for persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupAPT3

APT3 places scripts in the startup folder for persistence.

T1564.003
Hidden Window
GroupAPT3

APT3 has been known to use -WindowStyle Hidden to conceal PowerShell windows.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.