CISA et al.. (2024, February 7). PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure. Retrieved May 15, 2024.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupVolt Typhoon | Volt Typhoon has attempted to access hashed credentials from the LSASS process memory space. |
| T1003.003 NTDS |
GroupVolt Typhoon | Volt Typhoon has used ntds.util to create domain controller installation media containing usernames and password hashes. |
| T1005 Data from Local System |
GroupVolt Typhoon | Volt Typhoon has stolen files from a sensitive file server and the Active Directory database from targeted environments, and used Wevtutil to extract event log information. |
| T1006 Direct Volume Access |
GroupVolt Typhoon | Volt Typhoon has executed the Windows-native `vssadmin` command to create volume shadow copies. |
| T1007 System Service Discovery |
GroupVolt Typhoon | Volt Typhoon has used `net start` to list running services. |
| T1010 Application Window Discovery |
GroupVolt Typhoon | Volt Typhoon has collected window title information from compromised systems. |
| T1012 Query Registry |
GroupVolt Typhoon | Volt Typhoon has queried the Registry on compromised systems, `reg query hklm\software\`, for information on installed software including PuTTY. |
| T1016.001 Internet Connection Discovery |
GroupVolt Typhoon | Volt Typhoon has employed Ping to check network connectivity. |
| T1021.001 Remote Desktop Protocol |
GroupVolt Typhoon | Volt Typhoon has moved laterally to the Domain Controller via RDP using a compromised account with domain administrator privileges. |
| T1027.002 Software Packing |
GroupVolt Typhoon | Volt Typhoon has used the Ultimate Packer for Executables (UPX) to obfuscate the FRP client files BrightmetricAgent.exe and SMSvcService.ex) and the port scanning utility ScanLine. |
| T1033 System Owner/User Discovery |
GroupVolt Typhoon | Volt Typhoon has used public tools and executed the PowerShell command `Get-EventLog security -instanceid 4624` to identify associated user and computer account names. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupVolt Typhoon | Volt Typhoon has used legitimate looking filenames for compressed copies of the ntds.dit database and used names including cisco_up.exe, cl64.exe, vm3dservice.exe, watchdogd.exe, Win.exe, WmiPreSV.exe, and WmiPrvSE.exe for the Earthworm and Fast Reverse Proxy tools. |
| T1046 Network Service Discovery |
GroupVolt Typhoon | Volt Typhoon has used commercial tools, LOTL utilities, and appliances already present on the system for network service discovery. |
| T1047 Windows Management Instrumentation |
GroupVolt Typhoon | Volt Typhoon has leveraged WMIC for execution, remote system discovery, and to create and use temporary directories. |
| T1056.001 Keylogging |
GroupVolt Typhoon | Volt Typhoon has created and accessed a file named rult3uil.log on compromised domain controllers to capture keypresses and command execution. |
| T1057 Process Discovery |
GroupVolt Typhoon | Volt Typhoon has enumerated running processes on targeted systems including through the use of Tasklist. |
| T1059.001 PowerShell |
GroupVolt Typhoon | Volt Typhoon has used PowerShell including for remote system discovery. |
| T1059.003 Windows Command Shell |
GroupVolt Typhoon | Volt Typhoon has used the Windows command line to perform hands-on-keyboard activities in targeted environments including for discovery. |
| T1059.004 Unix Shell |
GroupVolt Typhoon | Volt Typhoon has used Brightmetricagent.exe which contains a command- line interface (CLI) library that can leverage command shells including Z Shell (zsh). |
| T1068 Exploitation for Privilege Escalation |
GroupVolt Typhoon | Volt Typhoon has gained initial access by exploiting privilege escalation vulnerabilities in the operating system or network services. |
| T1069 Permission Groups Discovery |
GroupVolt Typhoon | Volt Typhoon has used commercial tools, LOTL utilities, and appliances already present on the system for group and user discovery. |
| T1070.004 File Deletion |
GroupVolt Typhoon | Volt Typhoon has run `rd /S` to delete their working directories and deleted systeminfo.dat from `C:\Users\Public\Documentsfiles`. |
| T1078 Valid Accounts |
GroupVolt Typhoon | Volt Typhoon relies primarily on valid credentials for persistence. |
| T1078.002 Domain Accounts |
GroupVolt Typhoon | Volt Typhoon has used compromised domain accounts to authenticate to devices on compromised networks. |
| T1083 File and Directory Discovery |
GroupVolt Typhoon | Volt Typhoon has enumerated directories containing vulnerability testing and cyber related content and facilities data such as construction drawings. |
| T1087.001 Local Account |
GroupVolt Typhoon | Volt Typhoon has executed `net user` and `quser` to enumerate local account information. |
| T1090 Proxy |
GroupVolt Typhoon | Volt Typhoon has used compromised devices and customized versions of open source tools such as FRP (Fast Reverse Proxy), Earthworm, and Impacket to proxy network traffic. |
| T1090.001 Internal Proxy |
GroupVolt Typhoon | Volt Typhoon has used the built-in netsh `port proxy` command to create proxies on compromised systems to facilitate access. |
| T1090.003 Multi-hop Proxy |
GroupVolt Typhoon | Volt Typhoon has used multi-hop proxies for command-and-control infrastructure. |
| T1105 Ingress Tool Transfer |
GroupVolt Typhoon | Volt Typhoon has downloaded an outdated version of comsvcs.dll to a compromised domain controller in a non-standard folder. |
| T1112 Modify Registry |
GroupVolt Typhoon | Volt Typhoon has used `netsh` to create a PortProxy Registry modification on a compromised server running the Paessler Router Traffic Grapher (PRTG). |
| T1113 Screen Capture |
GroupVolt Typhoon | Volt Typhoon has obtained a screenshot of the victim's system using the gdi32.dll and gdiplus.dll libraries. |
| T1120 Peripheral Device Discovery |
GroupVolt Typhoon | Volt Typhoon has obtained victim's screen dimension and display device information. |
| T1124 System Time Discovery |
GroupVolt Typhoon | Volt Typhoon has obtained the victim's system timezone. |
| T1133 External Remote Services |
GroupVolt Typhoon | Volt Typhoon has used VPNs to connect to victim environments and enable post-exploitation actions. |
| T1190 Exploit Public-Facing Application |
GroupVolt Typhoon | Volt Typhoon has gained initial access through exploitation of multiple vulnerabilities in internet-facing software and appliances such as Fortinet, Ivanti (formerly Pulse Secure), NETGEAR, Citrix, and Cisco. |
| T1217 Browser Information Discovery |
GroupVolt Typhoon | Volt Typhoon has targeted the browsing history of network administrators. |
| T1218 System Binary Proxy Execution |
GroupVolt Typhoon | Volt Typhoon has used native tools and processes including living off the land binaries or “LOLBins" to maintain and expand access to the victim networks. |
| T1518 Software Discovery |
GroupVolt Typhoon | Volt Typhoon has queried the Registry on compromised systems for information on installed software. |
| T1552 Unsecured Credentials |
GroupVolt Typhoon | Volt Typhoon has obtained credentials insecurely stored on targeted network appliances. |
| T1552.004 Private Keys |
GroupVolt Typhoon | Volt Typhoon has accessed a Local State file that contains the AES key used to encrypt passwords stored in the Chrome browser. |
| T1555.003 Credentials from Web Browsers |
GroupVolt Typhoon | Volt Typhoon has targeted network administrator browser data including browsing history and stored credentials. |
| T1560.001 Archive via Utility |
GroupVolt Typhoon | Volt Typhoon has archived the ntds.dit database as a multi-volume password-protected archive with 7-Zip. |
| T1584.003 Virtual Private Server |
GroupVolt Typhoon | Volt Typhoon has compromised Virtual Private Servers (VPS) to proxy C2 traffic. |
| T1584.004 Server |
GroupVolt Typhoon | Volt Typhoon has used compromised Paessler Router Traffic Grapher (PRTG) servers from other organizations for C2. |
| T1584.005 Botnet |
GroupVolt Typhoon | Volt Typhoon has used compromised Cisco and NETGEAR end-of-life SOHO routers implanted with KV Botnet malware to support operations. |
| T1587.004 Exploits |
GroupVolt Typhoon | Volt Typhoon has exploited zero-day vulnerabilities for initial access. |
| T1588.002 Tool |
GroupVolt Typhoon | Volt Typhoon has used legitimate network and forensic tools and customized versions of open-source tools for C2. |
| T1588.006 Vulnerabilities |
GroupVolt Typhoon | Volt Typhoon has used publicly available exploit code for initial access. |
| T1589 Gather Victim Identity Information |
GroupVolt Typhoon | Volt Typhoon has gathered victim identify information during pre-compromise reconnaissance. |
Showing the first 50.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.