ATT&CKReferencesFireEye APT41 Aug 2019

FireEye APT41 Aug 2019

Fraser, N., et al. (2019, August 7). Double DragonAPT41, a dual espionage and cyber crime operation APT41. Retrieved September 23, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples51

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupAPT41

APT41 has used hashdump, Mimikatz, Procdump, and the Windows Credential Editor to dump password hashes from memory and authenticate to other user accounts.

T1008
Fallback Channels
GroupAPT41

APT41 used the Steam community page as a fallback mechanism for C2.

T1014
Rootkit
GroupAPT41

APT41 deployed rootkits on Linux systems.

T1016
System Network Configuration Discovery
GroupAPT41

APT41 collected MAC addresses from victim machines.

T1021.001
Remote Desktop Protocol
GroupAPT41

APT41 used RDP for lateral movement. APT41 used NATBypass to expose local RDP ports on compromised systems to the Internet.

T1033
System Owner/User Discovery
GroupAPT41

APT41 has executed whoami commands, including using the WMIEXEC utility to execute this on remote machines.

T1036.005
Match Legitimate Resource Name or Location
GroupAPT41

APT41 attempted to masquerade their files as popular anti-virus software.

T1046
Network Service Discovery
MalwareZxShell

ZxShell can launch port scans.

T1046
Network Service Discovery
GroupAPT41

APT41 used a malware variant called WIDETONE to conduct port scans on specified subnets.

T1047
Windows Management Instrumentation
GroupAPT41

APT41 used WMI in several ways, including for execution of commands via WMIEXEC as well as for persistence via PowerSploit. APT41 has executed files through Windows Management Instrumentation (WMI).

T1049
System Network Connections Discovery
GroupAPT41

APT41 has enumerated IP addresses of network resources and used the netstat command as part of network reconnaissance. The group has also used a malware variant, HIGHNOON, to enumerate active RDP sessions.

T1053.005
Scheduled Task
GroupAPT41

APT41 used a compromised account to create a scheduled task on a system.

T1055
Process Injection
GroupAPT41

APT41 malware TIDYELF loaded the main WINTERLOVE component by injecting it into the iexplore.exe process.

T1056.001
Keylogging
MalwareZxShell

ZxShell has a feature to capture a remote computer's keystrokes using a keylogger.

T1056.001
Keylogging
GroupAPT41

APT41 used a keylogger called GEARSHIFT on a target system.

T1059.001
PowerShell
GroupAPT41

APT41 leveraged PowerShell to deploy malware families in victims’ environments.

T1059.003
Windows Command Shell
GroupAPT41

APT41 used cmd.exe /c to execute commands on remote machines.
APT41 used a batch file to install persistence for the Cobalt Strike BEACON loader.

T1059.003
Windows Command Shell
MalwareZxShell

ZxShell can launch a reverse command shell.

T1070.003
Clear Command History
GroupAPT41

APT41 attempted to remove evidence of some of its activity by deleting Bash histories.

T1070.004
File Deletion
GroupAPT41

APT41 deleted files from the system.

T1070.004
File Deletion
MalwareZxShell

ZxShell can delete files from the system.

T1071.004
DNS
GroupAPT41

APT41 used DNS for C2 communications.

T1078
Valid Accounts
GroupAPT41

APT41 used compromised credentials to log on to other systems.

T1090
Proxy
MalwareZxShell

ZxShell can set up an HTTP or SOCKS proxy.

T1090
Proxy
GroupAPT41

APT41 used a tool called CLASSFON to covertly proxy network communications.

T1098.007
Additional Local or Domain Groups
GroupAPT41

APT41 has added user accounts to the User and Admin groups.

T1102.001
Dead Drop Resolver
GroupAPT41

APT41 used legitimate websites for C2 through dead drop resolvers (DDR), including GitHub, Pastebin, and Microsoft TechNet.

T1110
Brute Force
GroupAPT41

APT41 performed password brute-force attacks on the local admin account.

T1112
Modify Registry
GroupAPT41

APT41 used a malware variant called GOODLUCK to modify the registry in order to steal credentials.

T1113
Screen Capture
MalwareZxShell

ZxShell can capture screenshots.

T1133
External Remote Services
GroupAPT41

APT41 compromised an online billing/payment service using VPN access between a third-party service provider and the targeted payment service.

T1135
Network Share Discovery
GroupAPT41

APT41 used the net share command as part of network reconnaissance.

T1136.001
Local Account
GroupAPT41

APT41 has created user accounts.

T1195.002
Compromise Software Supply Chain
GroupAPT41

APT41 gained access to production environments where they could inject malicious code into legitimate, signed files and widely distribute them to end users.

T1203
Exploitation for Client Execution
GroupAPT41

APT41 leveraged the follow exploits in their operations: CVE-2012-0158, CVE-2015-1641, CVE-2017-0199, CVE-2017-11882, and CVE-2019-3396.

T1218.001
Compiled HTML File
GroupAPT41

APT41 used compiled HTML (.chm) files for targeting.

T1486
Data Encrypted for Impact
GroupAPT41

APT41 used a ransomware called Encryptor RaaS to encrypt files on the targeted systems and provide a ransom note to the user. APT41 also used Microsoft Bitlocker to encrypt workstations and Jetico’s BestCrypt to encrypt servers.

T1496.001
Compute Hijacking
GroupAPT41

APT41 deployed a Monero cryptocurrency mining tool in a victim’s environment.

T1499
Endpoint Denial of Service
MalwareZxShell

ZxShell has a feature to perform SYN flood attack on a host.

T1542.003
Bootkit
GroupAPT41

APT41 deployed Master Boot Record bootkits on Windows systems to hide their malware and maintain persistence on victim systems.

T1543.003
Windows Service
GroupAPT41

APT41 modified legitimate Windows services to install malware backdoors. APT41 created the StorSyncSvc service to provide persistence for Cobalt Strike.

T1546.008
Accessibility Features
GroupAPT41

APT41 leveraged sticky keys to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupAPT41

APT41 created and modified startup files for persistence. APT41 added a registry key in HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost to establish persistence for Cobalt Strike.

T1553.002
Code Signing
GroupAPT41

APT41 leveraged code-signing certificates to sign malware when targeting both gaming and non-gaming organizations.

T1560.001
Archive via Utility
GroupAPT41

APT41 created a RAR archive of targeted files for exfiltration. Additionally, APT41 used the makecab.exe utility to both download tools, such as NATBypass, to the victim network and to archive a file for exfiltration.

T1566.001
Spearphishing Attachment
GroupAPT41

APT41 sent spearphishing emails with attachments such as compiled HTML (.chm) files to initially compromise their victims.

T1568.002
Domain Generation Algorithms
MalwareShadowPad

ShadowPad uses a DGA that is based on the day of the month for C2 servers.

T1568.002
Domain Generation Algorithms
GroupAPT41

APT41 has used DGAs to change their C2 servers monthly.

T1574.001
DLL
GroupAPT41

APT41 has used search order hijacking to execute malicious payloads, such as Winnti for Windows. APT41 has also used legitimate executables to perform DLL side-loading of their malware.

T1588.002
Tool
GroupAPT41

APT41 has obtained and used tools such as Mimikatz, pwdump, PowerSploit, and Windows Credential Editor.

Showing the first 50.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.