NSA et al. (2023, May 24). People's Republic of China State-Sponsored Cyber Actor Living off the Land to Evade Detection. Retrieved July 27, 2023.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.003 NTDS |
GroupVolt Typhoon | Volt Typhoon has used ntds.util to create domain controller installation media containing usernames and password hashes. |
| T1005 Data from Local System |
GroupVolt Typhoon | Volt Typhoon has stolen files from a sensitive file server and the Active Directory database from targeted environments, and used Wevtutil to extract event log information. |
| T1012 Query Registry |
GroupVolt Typhoon | Volt Typhoon has queried the Registry on compromised systems, `reg query hklm\software\`, for information on installed software including PuTTY. |
| T1016 System Network Configuration Discovery |
GroupVolt Typhoon | Volt Typhoon has executed multiple commands to enumerate network topology and settings including `ipconfig`, `netsh interface firewall show all`, and `netsh interface portproxy show all`. |
| T1033 System Owner/User Discovery |
GroupVolt Typhoon | Volt Typhoon has used public tools and executed the PowerShell command `Get-EventLog security -instanceid 4624` to identify associated user and computer account names. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupVolt Typhoon | Volt Typhoon has used legitimate looking filenames for compressed copies of the ntds.dit database and used names including cisco_up.exe, cl64.exe, vm3dservice.exe, watchdogd.exe, Win.exe, WmiPreSV.exe, and WmiPrvSE.exe for the Earthworm and Fast Reverse Proxy tools. |
| T1047 Windows Management Instrumentation |
GroupVolt Typhoon | Volt Typhoon has leveraged WMIC for execution, remote system discovery, and to create and use temporary directories. |
| T1049 System Network Connections Discovery |
GroupVolt Typhoon | Volt Typhoon has used `netstat -ano` on compromised hosts to enumerate network connections. |
| T1059.001 PowerShell |
GroupVolt Typhoon | Volt Typhoon has used PowerShell including for remote system discovery. |
| T1059.003 Windows Command Shell |
GroupVolt Typhoon | Volt Typhoon has used the Windows command line to perform hands-on-keyboard activities in targeted environments including for discovery. |
| T1069.001 Local Groups |
GroupVolt Typhoon | Volt Typhoon has run `net localgroup administrators` in compromised environments to enumerate accounts. |
| T1074.001 Local Data Staging |
GroupVolt Typhoon | Volt Typhoon has saved stolen files including the `ntds.dit` database and the `SYSTEM` and `SECURITY` Registry hives locally to the `C:\Windows\Temp\` directory. |
| T1087.002 Domain Account |
GroupVolt Typhoon | Volt Typhoon has run `net group /dom` and `net group "Domain Admins" /dom` in compromised environments for account discovery. |
| T1090 Proxy |
GroupVolt Typhoon | Volt Typhoon has used compromised devices and customized versions of open source tools such as FRP (Fast Reverse Proxy), Earthworm, and Impacket to proxy network traffic. |
| T1518 Software Discovery |
GroupVolt Typhoon | Volt Typhoon has queried the Registry on compromised systems for information on installed software. |
| T1555 Credentials from Password Stores |
GroupVolt Typhoon | Volt Typhoon has attempted to obtain credentials from OpenSSH, realvnc, and PuTTY. |
| T1584.008 Network Devices |
GroupVolt Typhoon | Volt Typhoon has compromised small office and home office (SOHO) network edge devices, many of which were located in the same geographic area as the victim, to proxy network traffic. |
| T1654 Log Enumeration |
GroupVolt Typhoon | Volt Typhoon has used `wevtutil.exe` and the PowerShell command `Get-EventLog security` to enumerate Windows logs to search for successful logons. |
| T1680 Local Storage Discovery |
GroupVolt Typhoon | Volt Typhoon has discovered file system types, drive names, size, and free space on compromised systems. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.