ATT&CKReferencesVolexity Patchwork June 2018

Volexity Patchwork June 2018

Meltzer, M, et al. (2018, June 07). Patchwork APT Group Targets US Think Tanks. Retrieved July 16, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples21

TechniqueUsed byProcedure example
T1021.001
Remote Desktop Protocol
ToolQuasarRAT

QuasarRAT has a module for performing remote desktop access.

T1036.005
Match Legitimate Resource Name or Location
GroupPatchwork

Patchwork installed its payload in the startup programs folder as "Baidu Software Update." The group also adds its second stage payload to the startup programs as “Net Monitor." They have also dropped QuasarRAT binaries as files named microsoft_network.exe and crome.exe.

T1053.005
Scheduled Task
ToolQuasarRAT

QuasarRAT contains a .NET wrapper DLL for creating and managing scheduled tasks for maintaining persistence upon reboot.

T1056.001
Keylogging
ToolQuasarRAT

QuasarRAT has a built-in keylogger.

T1059.003
Windows Command Shell
GroupPatchwork

Patchwork ran a reverse shell with Meterpreter. Patchwork used JavaScript code and .SCT files on victim machines.

T1059.005
Visual Basic
GroupPatchwork

Patchwork used Visual Basic Scripts (VBS) on victim machines.

T1090
Proxy
ToolQuasarRAT

QuasarRAT can communicate over a reverse proxy using SOCKS5.

T1105
Ingress Tool Transfer
ToolQuasarRAT

QuasarRAT can download files to the victim’s machine and execute them.

T1125
Video Capture
ToolQuasarRAT

QuasarRAT can perform webcam viewing.

T1189
Drive-by Compromise
GroupPatchwork

Patchwork has used watering holes to deliver files with exploits to initial victims.

T1203
Exploitation for Client Execution
GroupPatchwork

Patchwork uses malicious documents to deliver remote execution exploits as part of. The group has previously exploited CVE-2017-8570, CVE-2012-1856, CVE-2014-4114, CVE-2017-0199, CVE-2017-11882, and CVE-2015-1641.

T1204.001
Malicious Link
GroupPatchwork

Patchwork has used spearphishing with links to try to get users to click, download and open malicious files.

T1204.002
Malicious File
GroupPatchwork

Patchwork embedded a malicious macro in a Word document and lured the victim to click on an icon to execute the malware.

T1552.001
Credentials In Files
ToolQuasarRAT

QuasarRAT can obtain passwords from FTP clients.

T1553.002
Code Signing
ToolQuasarRAT

A QuasarRAT .dll file is digitally signed by a certificate from AirVPN.

T1555
Credentials from Password Stores
ToolQuasarRAT

QuasarRAT can obtain passwords from common FTP clients.

T1555.003
Credentials from Web Browsers
ToolQuasarRAT

QuasarRAT can obtain passwords from common web browsers.

T1566.001
Spearphishing Attachment
GroupPatchwork

Patchwork has used spearphishing with an attachment to deliver files with exploits to initial victims.

T1573.001
Symmetric Cryptography
ToolQuasarRAT

QuasarRAT uses AES with a hardcoded pre-shared key to encrypt network communication.

T1588.002
Tool
GroupPatchwork

Patchwork has obtained and used open-source tools such as QuasarRAT.

T1598.003
Spearphishing Link
GroupPatchwork

Patchwork has used embedded image tags (known as web bugs) with unique, per-recipient tracking links in their emails for the purpose of identifying which recipients opened messages.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.