Meltzer, M, et al. (2018, June 07). Patchwork APT Group Targets US Think Tanks. Retrieved July 16, 2018.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1021.001 Remote Desktop Protocol |
ToolQuasarRAT | QuasarRAT has a module for performing remote desktop access. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupPatchwork | Patchwork installed its payload in the startup programs folder as "Baidu Software Update." The group also adds its second stage payload to the startup programs as “Net Monitor." They have also dropped QuasarRAT binaries as files named microsoft_network.exe and crome.exe. |
| T1053.005 Scheduled Task |
ToolQuasarRAT | QuasarRAT contains a .NET wrapper DLL for creating and managing scheduled tasks for maintaining persistence upon reboot. |
| T1056.001 Keylogging |
ToolQuasarRAT | QuasarRAT has a built-in keylogger. |
| T1059.003 Windows Command Shell |
GroupPatchwork | Patchwork ran a reverse shell with Meterpreter. Patchwork used JavaScript code and .SCT files on victim machines. |
| T1059.005 Visual Basic |
GroupPatchwork | Patchwork used Visual Basic Scripts (VBS) on victim machines. |
| T1090 Proxy |
ToolQuasarRAT | QuasarRAT can communicate over a reverse proxy using SOCKS5. |
| T1105 Ingress Tool Transfer |
ToolQuasarRAT | QuasarRAT can download files to the victim’s machine and execute them. |
| T1125 Video Capture |
ToolQuasarRAT | QuasarRAT can perform webcam viewing. |
| T1189 Drive-by Compromise |
GroupPatchwork | Patchwork has used watering holes to deliver files with exploits to initial victims. |
| T1203 Exploitation for Client Execution |
GroupPatchwork | Patchwork uses malicious documents to deliver remote execution exploits as part of. The group has previously exploited CVE-2017-8570, CVE-2012-1856, CVE-2014-4114, CVE-2017-0199, CVE-2017-11882, and CVE-2015-1641. |
| T1204.001 Malicious Link |
GroupPatchwork | Patchwork has used spearphishing with links to try to get users to click, download and open malicious files. |
| T1204.002 Malicious File |
GroupPatchwork | Patchwork embedded a malicious macro in a Word document and lured the victim to click on an icon to execute the malware. |
| T1552.001 Credentials In Files |
ToolQuasarRAT | QuasarRAT can obtain passwords from FTP clients. |
| T1553.002 Code Signing |
ToolQuasarRAT | A QuasarRAT .dll file is digitally signed by a certificate from AirVPN. |
| T1555 Credentials from Password Stores |
ToolQuasarRAT | QuasarRAT can obtain passwords from common FTP clients. |
| T1555.003 Credentials from Web Browsers |
ToolQuasarRAT | QuasarRAT can obtain passwords from common web browsers. |
| T1566.001 Spearphishing Attachment |
GroupPatchwork | Patchwork has used spearphishing with an attachment to deliver files with exploits to initial victims. |
| T1573.001 Symmetric Cryptography |
ToolQuasarRAT | QuasarRAT uses AES with a hardcoded pre-shared key to encrypt network communication. |
| T1588.002 Tool |
GroupPatchwork | Patchwork has obtained and used open-source tools such as QuasarRAT. |
| T1598.003 Spearphishing Link |
GroupPatchwork | Patchwork has used embedded image tags (known as web bugs) with unique, per-recipient tracking links in their emails for the purpose of identifying which recipients opened messages. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.