ATT&CKReferencesCymmetria Patchwork

Cymmetria Patchwork

Cymmetria. (2016). Unveiling Patchwork - The Copy-Paste APT. Retrieved November 17, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples17

TechniqueUsed byProcedure example
T1005
Data from Local System
GroupPatchwork

Patchwork collected and exfiltrated files from the infected system.

T1021.001
Remote Desktop Protocol
GroupPatchwork

Patchwork attempted to use RDP to move laterally.

T1033
System Owner/User Discovery
GroupPatchwork

Patchwork collected the victim username and whether it was running as admin, then sent the information to its C2 server.

T1036.005
Match Legitimate Resource Name or Location
GroupPatchwork

Patchwork installed its payload in the startup programs folder as "Baidu Software Update." The group also adds its second stage payload to the startup programs as “Net Monitor." They have also dropped QuasarRAT binaries as files named microsoft_network.exe and crome.exe.

T1055.012
Process Hollowing
GroupPatchwork

A Patchwork payload uses process hollowing to hide the UAC bypass vulnerability exploitation inside svchost.exe.

T1059.001
PowerShell
GroupPatchwork

Patchwork used PowerSploit to download payloads, run a reverse shell, and execute malware on the victim's machine.

T1059.003
Windows Command Shell
GroupPatchwork

Patchwork ran a reverse shell with Meterpreter. Patchwork used JavaScript code and .SCT files on victim machines.

T1082
System Information Discovery
GroupPatchwork

Patchwork collected the victim computer name, OS version, and architecture type and sent the information to its C2 server.

T1083
File and Directory Discovery
GroupPatchwork

A Patchwork payload has searched all fixed drives on the victim for files matching a specified list of extensions.

T1132.001
Standard Encoding
GroupPatchwork

Patchwork used Base64 to encode C2 traffic.

T1203
Exploitation for Client Execution
GroupPatchwork

Patchwork uses malicious documents to deliver remote execution exploits as part of. The group has previously exploited CVE-2017-8570, CVE-2012-1856, CVE-2014-4114, CVE-2017-0199, CVE-2017-11882, and CVE-2015-1641.

T1518.001
Security Software Discovery
GroupPatchwork

Patchwork scanned the “Program Files” directories for a directory with the string “Total Security” (the installation path of the “360 Total Security” antivirus tool).

T1547.001
Registry Run Keys / Startup Folder
GroupPatchwork

Patchwork has added the path of its second-stage malware to the startup folder to achieve persistence. One of its file stealers has also persisted by adding a Registry Run key.

T1548.002
Bypass User Account Control
GroupPatchwork

Patchwork bypassed User Access Control (UAC).

T1555.003
Credentials from Web Browsers
GroupPatchwork

Patchwork dumped the login data database from \AppData\Local\Google\Chrome\User Data\Default\Login Data.

T1566.001
Spearphishing Attachment
GroupPatchwork

Patchwork has used spearphishing with an attachment to deliver files with exploits to initial victims.

T1680
Local Storage Discovery
GroupPatchwork

Patchwork enumerated all available drives on the victim's machine.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.