ATT&CKReferencesTrendMicro Patchwork Dec 2017

TrendMicro Patchwork Dec 2017

Lunghi, D., et al. (2017, December). Untangling the Patchwork Cyberespionage Group. Retrieved July 10, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software3

Campaigns0

None recorded.

Procedure examples50

TechniqueUsed byProcedure example
T1025
Data from Removable Media
MalwareBADNEWS

BADNEWS copies files with certain extensions from USB devices to
a predefined directory.

T1027.001
Binary Padding
GroupPatchwork

Patchwork apparently altered NDiskMonitor samples by adding four bytes of random letters in a likely attempt to change the file hashes.

T1027.005
Indicator Removal from Tools
GroupPatchwork

Patchwork apparently altered NDiskMonitor samples by adding four bytes of random letters in a likely attempt to change the file hashes.

T1027.010
Command Obfuscation
GroupPatchwork

Patchwork has obfuscated a script with Crypto Obfuscator.

T1033
System Owner/User Discovery
GroupPatchwork

Patchwork collected the victim username and whether it was running as admin, then sent the information to its C2 server.

T1033
System Owner/User Discovery
MalwareNDiskMonitor

NDiskMonitor obtains the victim username and encrypts the information to send over its C2 channel.

T1036.001
Invalid Code Signature
MalwareBADNEWS

BADNEWS is sometimes signed with an invalid Authenticode certificate in an apparent effort to make it look more legitimate.

T1053.005
Scheduled Task
GroupPatchwork

A Patchwork file stealer can run a TaskScheduler DLL to add persistence.

T1055.001
Dynamic-link Library Injection
MalwareSocksbot

Socksbot creates a suspended svchost process and injects its DLL into it.

T1055.012
Process Hollowing
MalwareBADNEWS

BADNEWS has a command to download an .exe and use process hollowing to inject it into a new process.

T1056.001
Keylogging
MalwareBADNEWS

When it first starts, BADNEWS spawns a new thread to log keystrokes.

T1057
Process Discovery
MalwareSocksbot

Socksbot can list all running processes.

T1059.001
PowerShell
MalwareSocksbot

Socksbot can write and execute PowerShell scripts.

T1059.001
PowerShell
GroupPatchwork

Patchwork used PowerSploit to download payloads, run a reverse shell, and execute malware on the victim's machine.

T1059.003
Windows Command Shell
GroupPatchwork

Patchwork ran a reverse shell with Meterpreter. Patchwork used JavaScript code and .SCT files on victim machines.

T1059.003
Windows Command Shell
MalwareBADNEWS

BADNEWS is capable of executing commands via cmd.exe.

T1059.005
Visual Basic
GroupPatchwork

Patchwork used Visual Basic Scripts (VBS) on victim machines.

T1070.004
File Deletion
GroupPatchwork

Patchwork removed certain files and replaced them so they could not be retrieved.

T1074.001
Local Data Staging
GroupPatchwork

Patchwork copied all targeted files to a directory called index that was eventually uploaded to the C&C server.

T1074.001
Local Data Staging
MalwareBADNEWS

BADNEWS copies documents under 15MB found on the victim system to is the user's %temp%\SMB\ folder. It also copies files from USB devices to a predefined directory.

T1082
System Information Discovery
MalwareNDiskMonitor

NDiskMonitor obtains the victim computer name and encrypts the information to send over its C2 channel.

T1082
System Information Discovery
GroupPatchwork

Patchwork collected the victim computer name, OS version, and architecture type and sent the information to its C2 server.

T1083
File and Directory Discovery
MalwareNDiskMonitor

NDiskMonitor can obtain a list of all files and directories as well as logical drives.

T1083
File and Directory Discovery
GroupPatchwork

A Patchwork payload has searched all fixed drives on the victim for files matching a specified list of extensions.

T1083
File and Directory Discovery
MalwareBADNEWS

BADNEWS identifies files with certain extensions from USB devices, then copies them to a predefined directory.

T1090
Proxy
MalwareSocksbot

Socksbot can start SOCKS proxy threads.

T1102.001
Dead Drop Resolver
MalwareBADNEWS

BADNEWS collects C2 information via a dead drop resolver.

T1102.002
Bidirectional Communication
MalwareBADNEWS

BADNEWS can use multiple C2 channels, including RSS feeds, Github, forums, and blogs.

T1105
Ingress Tool Transfer
GroupPatchwork

Patchwork payloads download additional files from the C2 server.

T1105
Ingress Tool Transfer
MalwareBADNEWS

BADNEWS is capable of downloading additional files through C2 channels, including a new version of itself.

T1105
Ingress Tool Transfer
MalwareNDiskMonitor

NDiskMonitor can download and execute a file from given URL.

T1106
Native API
MalwareBADNEWS

BADNEWS has a command to download an .exe and execute it via CreateProcess API. It can also run with ShellExecute.

T1112
Modify Registry
GroupPatchwork

A Patchwork payload deletes Resiliency Registry keys created by Microsoft Office applications in an apparent effort to trick users into thinking there were no issues during application runs.

T1113
Screen Capture
MalwareSocksbot

Socksbot can take screenshots.

T1119
Automated Collection
MalwareBADNEWS

BADNEWS monitors USB devices and copies files with certain extensions to a predefined directory.

T1119
Automated Collection
GroupPatchwork

Patchwork developed a file stealer to search C:\ and collect files with certain extensions. Patchwork also executed a script to enumerate all drives, store them as a list, and upload generated files to the C2 server.

T1120
Peripheral Device Discovery
MalwareBADNEWS

BADNEWS checks for new hard drives on the victim, such as USB devices, by listening for the WM_DEVICECHANGE window message.

T1132.001
Standard Encoding
MalwareBADNEWS

BADNEWS encodes C2 traffic with base64.

T1203
Exploitation for Client Execution
GroupPatchwork

Patchwork uses malicious documents to deliver remote execution exploits as part of. The group has previously exploited CVE-2017-8570, CVE-2012-1856, CVE-2014-4114, CVE-2017-0199, CVE-2017-11882, and CVE-2015-1641.

T1204.001
Malicious Link
GroupPatchwork

Patchwork has used spearphishing with links to try to get users to click, download and open malicious files.

T1204.002
Malicious File
GroupPatchwork

Patchwork embedded a malicious macro in a Word document and lured the victim to click on an icon to execute the malware.

T1547.001
Registry Run Keys / Startup Folder
GroupPatchwork

Patchwork has added the path of its second-stage malware to the startup folder to achieve persistence. One of its file stealers has also persisted by adding a Registry Run key.

T1559.002
Dynamic Data Exchange
GroupPatchwork

Patchwork leveraged the DDE protocol to deliver their malware.

T1560
Archive Collected Data
GroupPatchwork

Patchwork encrypted the collected files' path with AES and then encoded them with base64.

T1566.001
Spearphishing Attachment
GroupPatchwork

Patchwork has used spearphishing with an attachment to deliver files with exploits to initial victims.

T1566.002
Spearphishing Link
GroupPatchwork

Patchwork has used spearphishing with links to deliver files with exploits to initial victims.

T1573.001
Symmetric Cryptography
MalwareBADNEWS

BADNEWS encrypts C2 data with a ROR by 3 and an XOR by 0x23.

T1573.001
Symmetric Cryptography
MalwareNDiskMonitor

NDiskMonitor uses AES to encrypt certain information sent over its C2 channel.

T1574.001
DLL
GroupPatchwork

A Patchwork .dll that contains BADNEWS is loaded and executed using DLL side-loading.

T1680
Local Storage Discovery
GroupPatchwork

Patchwork enumerated all available drives on the victim's machine.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.