Jazi, H. (2021, June 1). Kimsuky APT continues to target South Korean government using AppleSeed backdoor. Retrieved June 10, 2021.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareAppleSeed | AppleSeed can collect data on a compromised host. |
| T1008 Fallback Channels |
MalwareAppleSeed | AppleSeed can use a second channel for C2 when the primary channel is in upload mode. |
| T1016 System Network Configuration Discovery |
MalwareAppleSeed | AppleSeed can identify the IP of a targeted system. |
| T1025 Data from Removable Media |
MalwareAppleSeed | AppleSeed can find and collect data from removable media devices. |
| T1027 Obfuscated Files or Information |
MalwareAppleSeed | AppleSeed has the ability to Base64 encode its payload and custom encrypt API calls. |
| T1027.002 Software Packing |
GroupKimsuky | Kimsuky has packed malware with UPX. |
| T1027.002 Software Packing |
MalwareAppleSeed | AppleSeed has used UPX packers for its payload DLL. |
| T1036 Masquerading |
MalwareAppleSeed | AppleSeed can disguise JavaScript files as PDFs. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareAppleSeed | AppleSeed has the ability to rename its payload to ESTCommon.dll to masquerade as a DLL belonging to ESTsecurity. |
| T1041 Exfiltration Over C2 Channel |
MalwareAppleSeed | AppleSeed can exfiltrate files via the C2 channel. |
| T1056.001 Keylogging |
MalwareAppleSeed | AppleSeed can use |
| T1057 Process Discovery |
MalwareAppleSeed | AppleSeed can enumerate the current process on a compromised host. |
| T1059.001 PowerShell |
MalwareAppleSeed | AppleSeed has the ability to execute its payload via PowerShell. |
| T1059.007 JavaScript |
MalwareAppleSeed | AppleSeed has the ability to use JavaScript to execute PowerShell. |
| T1070.004 File Deletion |
MalwareAppleSeed | AppleSeed can delete files from a compromised host after they are exfiltrated. |
| T1071.001 Web Protocols |
MalwareAppleSeed | AppleSeed has the ability to communicate with C2 over HTTP. |
| T1074.001 Local Data Staging |
MalwareAppleSeed | AppleSeed can stage files in a central location prior to exfiltration. |
| T1082 System Information Discovery |
MalwareAppleSeed | AppleSeed can identify the OS version of a targeted system. |
| T1083 File and Directory Discovery |
MalwareAppleSeed | AppleSeed has the ability to search for .txt, .ppt, .hwp, .pdf, and .doc files in specified directories. |
| T1106 Native API |
MalwareAppleSeed | AppleSeed has the ability to use multiple dynamically resolved API calls. |
| T1113 Screen Capture |
MalwareAppleSeed | AppleSeed can take screenshots on a compromised host by calling a series of APIs. |
| T1124 System Time Discovery |
MalwareAppleSeed | AppleSeed can pull a timestamp from the victim's machine. |
| T1134 Access Token Manipulation |
MalwareAppleSeed | AppleSeed can gain system level privilege by passing |
| T1140 Deobfuscate/Decode Files or Information |
MalwareAppleSeed | AppleSeed can decode its payload prior to execution. |
| T1204.002 Malicious File |
MalwareAppleSeed | AppleSeed can achieve execution through users running malicious file attachments distributed via email. |
| T1204.002 Malicious File |
GroupKimsuky | Kimsuky has used spearphishing attachments to entice victims into opening malicious files, including LNK files disguised with tailored filenames and fake extensions. Kimsuky has also delivered malicious payloads within archive files (e.g., ZIP), which display decoy documents upon execution while running malicious code in the background. |
| T1218.010 Regsvr32 |
MalwareAppleSeed | AppleSeed can call regsvr32.exe for execution. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareAppleSeed | AppleSeed has the ability to create the Registry key name |
| T1560.001 Archive via Utility |
MalwareAppleSeed | AppleSeed can zip and encrypt data collected on a target system. |
| T1566.001 Spearphishing Attachment |
GroupKimsuky | Kimsuky has used emails containing Word, Excel and/or HWP (Hangul Word Processor) documents in their spearphishing campaigns. Kimsuky has also distributed emails with attached compressed zip files that contained malicious .LNK files masquerading as legitimate files. Kimsuky has delivered tailored PDF documents that contain malicious links. |
| T1566.001 Spearphishing Attachment |
MalwareAppleSeed | AppleSeed has been distributed to victims through malicious e-mail attachments. |
| T1583.001 Domains |
GroupKimsuky | Kimsuky has registered domains to spoof targeted organizations and trusted third parties including search engines, web platforms, and cryptocurrency exchanges. |
| T1586.002 Email Accounts |
GroupKimsuky | Kimsuky has compromised email accounts to send spearphishing e-mails. |
| T1589.002 Email Addresses |
GroupKimsuky | Kimsuky has collected valid email addresses including personal accounts that were subsequently used for spearphishing and other forms of social engineering. |
| T1593.001 Social Media |
GroupKimsuky | Kimsuky has used Twitter to monitor potential victims and to prepare targeted phishing e-mails. |
| T1598.003 Spearphishing Link |
GroupKimsuky | Kimsuky has used links in e-mail to steal account information including web beacons for target profiling. Kimsuky has also utilized QR codes (also known as Quishing) to direct victims to malicious links through the reliance of a mobile device to scan a code with an embedded malicious URL. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.