CISA, FBI, CNMF. (2020, October 27). https://us-cert.cisa.gov/ncas/alerts/aa20-301a. Retrieved November 4, 2020.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupKimsuky | Kimsuky has gathered credentials using Mimikatz and ProcDump. |
| T1036.004 Masquerade Task or Service |
GroupKimsuky | Kimsuky has disguised services to appear as benign software or related to operating system functions. |
| T1040 Network Sniffing |
GroupKimsuky | Kimsuky has used the Nirsoft SniffPass network sniffer to obtain passwords sent over non-secure protocols. |
| T1056.001 Keylogging |
GroupKimsuky | Kimsuky has used a PowerShell-based keylogger as well as a tool called MECHANICAL to log keystrokes. Kimsuky has also leveraged Native Windows API functions such as `GetAsyncKeyState()` along with others to capture keystrokes every 50 milliseconds and stores data in a file stored in the temp directory. |
| T1059.001 PowerShell |
GroupKimsuky | Kimsuky has executed a variety of PowerShell scripts including Invoke-Mimikatz. Kimsuky has also utilized PowerShell scripts for execution, persistence, and defense evasion. Kimsuky has leveraged PowerShell’s cmdlet `Expand-Archive` to extract contents of zip files into the same directory. Kimsuky has employed ClickFix type tactics enticing victims to copy and paste malicious PowerShell commands and scripts, where the scripts ultimately led to QuasarRAT. |
| T1059.006 Python |
GroupKimsuky | Kimsuky has used a macOS Python implant to gather data as well as MailFetcher.py code to automatically collect email data. |
| T1059.007 JavaScript |
GroupKimsuky | Kimsuky has used JScript for logging and downloading additional tools. Kimsuky has used TRANSLATEXT, which contained four Javascript files for bypassing defenses, collecting sensitive information and screenshots, and exfiltrating data. |
| T1071.003 Mail Protocols |
GroupKimsuky | Kimsuky has used e-mail to send exfiltrated data to C2 servers. |
| T1074.001 Local Data Staging |
GroupKimsuky | Kimsuky has staged collected data files under |
| T1105 Ingress Tool Transfer |
MalwareBabyShark | BabyShark has downloaded additional files from the C2. |
| T1112 Modify Registry |
GroupKimsuky | Kimsuky has modified Registry settings for default file associations to enable all macros and for persistence. Kimsuky has also modified the registry entry for `HKCU:\Software\Microsoft\Windows\CurrentVersion\Run` registry key for persistence with the name WindowsSecurityCheck. |
| T1114.003 Email Forwarding Rule |
GroupKimsuky | Kimsuky has set auto-forward rules on victim's e-mail accounts. |
| T1133 External Remote Services |
GroupKimsuky | Kimsuky has used RDP to establish persistence. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareBabyShark | BabyShark has the ability to decode downloaded files prior to execution. |
| T1204.002 Malicious File |
GroupKimsuky | Kimsuky has used spearphishing attachments to entice victims into opening malicious files, including LNK files disguised with tailored filenames and fake extensions. Kimsuky has also delivered malicious payloads within archive files (e.g., ZIP), which display decoy documents upon execution while running malicious code in the background. |
| T1218.005 Mshta |
MalwareBabyShark | BabyShark has used mshta.exe to download and execute applications from a remote server. |
| T1218.005 Mshta |
GroupKimsuky | Kimsuky has used mshta.exe to run malicious scripts on the system. |
| T1505.003 Web Shell |
GroupKimsuky | Kimsuky has used modified versions of open source PHP web shells to maintain access, often adding "Dinosaur" references within the code. |
| T1543.003 Windows Service |
GroupKimsuky | Kimsuky has created new services for persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupKimsuky | Kimsuky has placed scripts in the startup folder for persistence and modified the `HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce` Registry key. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareBabyShark | BabyShark has added a Registry key to ensure all future macros are enabled for Microsoft Word and Excel as well as for additional persistence. |
| T1550.002 Pass the Hash |
GroupKimsuky | Kimsuky has used pass the hash for authentication to remote access software used in C2. |
| T1555.003 Credentials from Web Browsers |
GroupKimsuky | Kimsuky has used browser extensions including Google Chrome to steal passwords and cookies from browsers. Kimsuky has also used Nirsoft's WebBrowserPassView tool to dump the passwords obtained from victims. |
| T1557 Adversary-in-the-Middle |
GroupKimsuky | Kimsuky has used modified versions of PHProxy to examine web traffic between the victim and the accessed website. |
| T1583.001 Domains |
GroupKimsuky | Kimsuky has registered domains to spoof targeted organizations and trusted third parties including search engines, web platforms, and cryptocurrency exchanges. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.