Fraser, N., et al. (2019, August 7). Double DragonAPT41, a dual espionage and cyber crime operation APT41. Retrieved September 23, 2019.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupAPT41 | APT41 has used hashdump, Mimikatz, Procdump, and the Windows Credential Editor to dump password hashes from memory and authenticate to other user accounts. |
| T1008 Fallback Channels |
GroupAPT41 | APT41 used the Steam community page as a fallback mechanism for C2. |
| T1014 Rootkit |
GroupAPT41 | APT41 deployed rootkits on Linux systems. |
| T1016 System Network Configuration Discovery |
GroupAPT41 | APT41 collected MAC addresses from victim machines. |
| T1021.001 Remote Desktop Protocol |
GroupAPT41 | APT41 used RDP for lateral movement. APT41 used NATBypass to expose local RDP ports on compromised systems to the Internet. |
| T1033 System Owner/User Discovery |
GroupAPT41 | APT41 has executed |
| T1036.005 Match Legitimate Resource Name or Location |
GroupAPT41 | APT41 attempted to masquerade their files as popular anti-virus software. |
| T1046 Network Service Discovery |
MalwareZxShell | ZxShell can launch port scans. |
| T1046 Network Service Discovery |
GroupAPT41 | APT41 used a malware variant called WIDETONE to conduct port scans on specified subnets. |
| T1047 Windows Management Instrumentation |
GroupAPT41 | APT41 used WMI in several ways, including for execution of commands via WMIEXEC as well as for persistence via PowerSploit. APT41 has executed files through Windows Management Instrumentation (WMI). |
| T1049 System Network Connections Discovery |
GroupAPT41 | APT41 has enumerated IP addresses of network resources and used the |
| T1053.005 Scheduled Task |
GroupAPT41 | APT41 used a compromised account to create a scheduled task on a system. |
| T1055 Process Injection |
GroupAPT41 | APT41 malware TIDYELF loaded the main WINTERLOVE component by injecting it into the iexplore.exe process. |
| T1056.001 Keylogging |
MalwareZxShell | ZxShell has a feature to capture a remote computer's keystrokes using a keylogger. |
| T1056.001 Keylogging |
GroupAPT41 | APT41 used a keylogger called GEARSHIFT on a target system. |
| T1059.001 PowerShell |
GroupAPT41 | APT41 leveraged PowerShell to deploy malware families in victims’ environments. |
| T1059.003 Windows Command Shell |
GroupAPT41 | APT41 used |
| T1059.003 Windows Command Shell |
MalwareZxShell | ZxShell can launch a reverse command shell. |
| T1070.003 Clear Command History |
GroupAPT41 | APT41 attempted to remove evidence of some of its activity by deleting Bash histories. |
| T1070.004 File Deletion |
GroupAPT41 | APT41 deleted files from the system. |
| T1070.004 File Deletion |
MalwareZxShell | ZxShell can delete files from the system. |
| T1071.004 DNS |
GroupAPT41 | APT41 used DNS for C2 communications. |
| T1078 Valid Accounts |
GroupAPT41 | APT41 used compromised credentials to log on to other systems. |
| T1090 Proxy |
MalwareZxShell | ZxShell can set up an HTTP or SOCKS proxy. |
| T1090 Proxy |
GroupAPT41 | APT41 used a tool called CLASSFON to covertly proxy network communications. |
| T1098.007 Additional Local or Domain Groups |
GroupAPT41 | APT41 has added user accounts to the User and Admin groups. |
| T1102.001 Dead Drop Resolver |
GroupAPT41 | APT41 used legitimate websites for C2 through dead drop resolvers (DDR), including GitHub, Pastebin, and Microsoft TechNet. |
| T1110 Brute Force |
GroupAPT41 | APT41 performed password brute-force attacks on the local admin account. |
| T1112 Modify Registry |
GroupAPT41 | APT41 used a malware variant called GOODLUCK to modify the registry in order to steal credentials. |
| T1113 Screen Capture |
MalwareZxShell | ZxShell can capture screenshots. |
| T1133 External Remote Services |
GroupAPT41 | APT41 compromised an online billing/payment service using VPN access between a third-party service provider and the targeted payment service. |
| T1135 Network Share Discovery |
GroupAPT41 | APT41 used the |
| T1136.001 Local Account |
GroupAPT41 | APT41 has created user accounts. |
| T1195.002 Compromise Software Supply Chain |
GroupAPT41 | APT41 gained access to production environments where they could inject malicious code into legitimate, signed files and widely distribute them to end users. |
| T1203 Exploitation for Client Execution |
GroupAPT41 | APT41 leveraged the follow exploits in their operations: CVE-2012-0158, CVE-2015-1641, CVE-2017-0199, CVE-2017-11882, and CVE-2019-3396. |
| T1218.001 Compiled HTML File |
GroupAPT41 | APT41 used compiled HTML (.chm) files for targeting. |
| T1486 Data Encrypted for Impact |
GroupAPT41 | APT41 used a ransomware called Encryptor RaaS to encrypt files on the targeted systems and provide a ransom note to the user. APT41 also used Microsoft Bitlocker to encrypt workstations and Jetico’s BestCrypt to encrypt servers. |
| T1496.001 Compute Hijacking |
GroupAPT41 | APT41 deployed a Monero cryptocurrency mining tool in a victim’s environment. |
| T1499 Endpoint Denial of Service |
MalwareZxShell | ZxShell has a feature to perform SYN flood attack on a host. |
| T1542.003 Bootkit |
GroupAPT41 | APT41 deployed Master Boot Record bootkits on Windows systems to hide their malware and maintain persistence on victim systems. |
| T1543.003 Windows Service |
GroupAPT41 | APT41 modified legitimate Windows services to install malware backdoors. APT41 created the StorSyncSvc service to provide persistence for Cobalt Strike. |
| T1546.008 Accessibility Features |
GroupAPT41 | APT41 leveraged sticky keys to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupAPT41 | APT41 created and modified startup files for persistence. APT41 added a registry key in |
| T1553.002 Code Signing |
GroupAPT41 | APT41 leveraged code-signing certificates to sign malware when targeting both gaming and non-gaming organizations. |
| T1560.001 Archive via Utility |
GroupAPT41 | APT41 created a RAR archive of targeted files for exfiltration. Additionally, APT41 used the makecab.exe utility to both download tools, such as NATBypass, to the victim network and to archive a file for exfiltration. |
| T1566.001 Spearphishing Attachment |
GroupAPT41 | APT41 sent spearphishing emails with attachments such as compiled HTML (.chm) files to initially compromise their victims. |
| T1568.002 Domain Generation Algorithms |
MalwareShadowPad | ShadowPad uses a DGA that is based on the day of the month for C2 servers. |
| T1568.002 Domain Generation Algorithms |
GroupAPT41 | APT41 has used DGAs to change their C2 servers monthly. |
| T1574.001 DLL |
GroupAPT41 | APT41 has used search order hijacking to execute malicious payloads, such as Winnti for Windows. APT41 has also used legitimate executables to perform DLL side-loading of their malware. |
| T1588.002 Tool |
GroupAPT41 | APT41 has obtained and used tools such as Mimikatz, pwdump, PowerSploit, and Windows Credential Editor. |
Showing the first 50.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.