ATT&CKReferencesSecureworks BRONZE SILHOUETTE May 2023

Secureworks BRONZE SILHOUETTE May 2023

Counter Threat Unit Research Team. (2023, May 24). Chinese Cyberespionage Group BRONZE SILHOUETTE Targets U.S. Government and Defense Organizations. Retrieved July 27, 2023.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples24

TechniqueUsed byProcedure example
T1003.003
NTDS
GroupVolt Typhoon

Volt Typhoon has used ntds.util to create domain controller installation media containing usernames and password hashes.

T1005
Data from Local System
GroupVolt Typhoon

Volt Typhoon has stolen files from a sensitive file server and the Active Directory database from targeted environments, and used Wevtutil to extract event log information.

T1018
Remote System Discovery
GroupVolt Typhoon

Volt Typhoon has used multiple methods, including Ping, to enumerate systems on compromised networks.

T1033
System Owner/User Discovery
GroupVolt Typhoon

Volt Typhoon has used public tools and executed the PowerShell command `Get-EventLog security -instanceid 4624` to identify associated user and computer account names.

T1036.005
Match Legitimate Resource Name or Location
GroupVolt Typhoon

Volt Typhoon has used legitimate looking filenames for compressed copies of the ntds.dit database and used names including cisco_up.exe, cl64.exe, vm3dservice.exe, watchdogd.exe, Win.exe, WmiPreSV.exe, and WmiPrvSE.exe for the Earthworm and Fast Reverse Proxy tools.

T1036.008
Masquerade File Type
GroupVolt Typhoon

Volt Typhoon has appended copies of the ntds.dit database with a .gif file extension.

T1047
Windows Management Instrumentation
GroupVolt Typhoon

Volt Typhoon has leveraged WMIC for execution, remote system discovery, and to create and use temporary directories.

T1049
System Network Connections Discovery
GroupVolt Typhoon

Volt Typhoon has used `netstat -ano` on compromised hosts to enumerate network connections.

T1057
Process Discovery
GroupVolt Typhoon

Volt Typhoon has enumerated running processes on targeted systems including through the use of Tasklist.

T1059.003
Windows Command Shell
GroupVolt Typhoon

Volt Typhoon has used the Windows command line to perform hands-on-keyboard activities in targeted environments including for discovery.

T1069.002
Domain Groups
GroupVolt Typhoon

Volt Typhoon has run `net group` in compromised environments to discover domain groups.

T1070.004
File Deletion
GroupVolt Typhoon

Volt Typhoon has run `rd /S` to delete their working directories and deleted systeminfo.dat from `C:\Users\Public\Documentsfiles`.

T1070.007
Clear Network Connection History and Configurations
GroupVolt Typhoon

Volt Typhoon has inspected server logs to remove their IPs.

T1074.001
Local Data Staging
GroupVolt Typhoon

Volt Typhoon has saved stolen files including the `ntds.dit` database and the `SYSTEM` and `SECURITY` Registry hives locally to the `C:\Windows\Temp\` directory.

T1078.002
Domain Accounts
GroupVolt Typhoon

Volt Typhoon has used compromised domain accounts to authenticate to devices on compromised networks.

T1087.002
Domain Account
GroupVolt Typhoon

Volt Typhoon has run `net group /dom` and `net group "Domain Admins" /dom` in compromised environments for account discovery.

T1140
Deobfuscate/Decode Files or Information
GroupVolt Typhoon

Volt Typhoon has used Base64-encoded data to transfer payloads and commands, including deobfuscation via certutil.

T1190
Exploit Public-Facing Application
GroupVolt Typhoon

Volt Typhoon has gained initial access through exploitation of multiple vulnerabilities in internet-facing software and appliances such as Fortinet, Ivanti (formerly Pulse Secure), NETGEAR, Citrix, and Cisco.

T1505.003
Web Shell
GroupVolt Typhoon

Volt Typhoon has used webshells, including ones named AuditReport.jspx and iisstart.aspx, in compromised environments.

T1560.001
Archive via Utility
GroupVolt Typhoon

Volt Typhoon has archived the ntds.dit database as a multi-volume password-protected archive with 7-Zip.

T1570
Lateral Tool Transfer
GroupVolt Typhoon

Volt Typhoon has copied web shells between servers in targeted environments.

T1573.001
Symmetric Cryptography
GroupVolt Typhoon

Volt Typhoon has used a version of the Awen web shell that employed AES encryption and decryption for C2 communications.

T1584.004
Server
GroupVolt Typhoon

Volt Typhoon has used compromised Paessler Router Traffic Grapher (PRTG) servers from other organizations for C2.

T1680
Local Storage Discovery
GroupVolt Typhoon

Volt Typhoon has discovered file system types, drive names, size, and free space on compromised systems.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.