Rostovcev, N. (2021, June 10). Big airline heist APT41 likely behind a third-party attack on Air India. Retrieved August 26, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupAPT41 | APT41 has used hashdump, Mimikatz, Procdump, and the Windows Credential Editor to dump password hashes from memory and authenticate to other user accounts. |
| T1005 Data from Local System |
GroupAPT41 | APT41 has uploaded files and data from a compromised host. |
| T1016 System Network Configuration Discovery |
GroupAPT41 | APT41 collected MAC addresses from victim machines. |
| T1036.004 Masquerade Task or Service |
GroupAPT41 | APT41 has created services to appear as benign system tools. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupAPT41 | APT41 attempted to masquerade their files as popular anti-virus software. |
| T1047 Windows Management Instrumentation |
GroupAPT41 | APT41 used WMI in several ways, including for execution of commands via WMIEXEC as well as for persistence via PowerSploit. APT41 has executed files through Windows Management Instrumentation (WMI). |
| T1049 System Network Connections Discovery |
GroupAPT41 | APT41 has enumerated IP addresses of network resources and used the |
| T1071.004 DNS |
GroupAPT41 | APT41 used DNS for C2 communications. |
| T1105 Ingress Tool Transfer |
GroupAPT41 | APT41 used certutil to download additional files. APT41 downloaded post-exploitation tools such as Cobalt Strike via command shell following initial access. APT41 has uploaded Procdump and NATBypass to a staging directory and has used these tools in follow-on activities. |
| T1112 Modify Registry |
GroupAPT41 | APT41 used a malware variant called GOODLUCK to modify the registry in order to steal credentials. |
| T1135 Network Share Discovery |
GroupAPT41 | APT41 used the |
| T1543.003 Windows Service |
GroupAPT41 | APT41 modified legitimate Windows services to install malware backdoors. APT41 created the StorSyncSvc service to provide persistence for Cobalt Strike. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupAPT41 | APT41 created and modified startup files for persistence. APT41 added a registry key in |
| T1553.002 Code Signing |
GroupAPT41 | APT41 leveraged code-signing certificates to sign malware when targeting both gaming and non-gaming organizations. |
| T1569.002 Service Execution |
GroupAPT41 | APT41 used svchost.exe and Net to execute a system service installed to launch a Cobalt Strike BEACON loader. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.