Slowik, J. (2021, October). THE BAFFLING BERSERK BEAR: A DECADE’S ACTIVITY TARGETING CRITICAL INFRASTRUCTURE. Retrieved December 6, 2021.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareBackdoor.Oldrea | Backdoor.Oldrea collects information about the Internet adapter configuration. |
| T1018 Remote System Discovery |
MalwareBackdoor.Oldrea | Backdoor.Oldrea can enumerate and map ICS-specific systems in victim environments. |
| T1046 Network Service Discovery |
MalwareBackdoor.Oldrea | Backdoor.Oldrea can use a network scanning module to identify ICS-related ports. |
| T1055 Process Injection |
MalwareBackdoor.Oldrea | Backdoor.Oldrea injects itself into explorer.exe. |
| T1078 Valid Accounts |
GroupDragonfly | Dragonfly has compromised user credentials and used valid accounts for operations. |
| T1082 System Information Discovery |
MalwareBackdoor.Oldrea | Backdoor.Oldrea collects information about the OS and computer name. |
| T1083 File and Directory Discovery |
GroupDragonfly | Dragonfly has used a batch script to gather folder and file names from victim hosts. |
| T1105 Ingress Tool Transfer |
MalwareBackdoor.Oldrea | Backdoor.Oldrea can download additional modules from C2. |
| T1113 Screen Capture |
GroupDragonfly | Dragonfly has performed screen captures of victims, including by using a tool, scr.exe (which matched the hash of ScreenUtil). |
| T1187 Forced Authentication |
GroupDragonfly | Dragonfly has gathered hashed user credentials over SMB using spearphishing attachments with external resource links and by modifying .LNK file icon resources to collect credentials from virtualized systems. |
| T1189 Drive-by Compromise |
GroupDragonfly | Dragonfly has compromised targets via strategic web compromise (SWC) utilizing a custom exploit kit. |
| T1195.002 Compromise Software Supply Chain |
GroupDragonfly | Dragonfly has placed trojanized installers for control system software on legitimate vendor app stores. |
| T1203 Exploitation for Client Execution |
GroupDragonfly | Dragonfly has exploited CVE-2011-0611 in Adobe Flash Player to gain execution on a targeted system. |
| T1204.002 Malicious File |
GroupDragonfly | Dragonfly has used various forms of spearphishing in attempts to get users to open malicious attachments. |
| T1218.011 Rundll32 |
MalwareBackdoor.Oldrea | Backdoor.Oldrea can use rundll32 for execution on compromised hosts. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareBackdoor.Oldrea | Backdoor.Oldrea adds Registry Run keys to achieve persistence. |
| T1566.001 Spearphishing Attachment |
GroupDragonfly | Dragonfly has sent emails with malicious attachments to gain initial access. |
| T1583.003 Virtual Private Server |
GroupDragonfly | Dragonfly has acquired VPS infrastructure for use in malicious campaigns. |
| T1584.004 Server |
GroupDragonfly | Dragonfly has compromised legitimate websites to host C2 and malware modules. |
| T1591.002 Business Relationships |
GroupDragonfly | Dragonfly has collected open source information to identify relationships between organizations for targeting purposes. |
| T1608.004 Drive-by Target |
GroupDragonfly | Dragonfly has compromised websites to redirect traffic and to host exploit kits. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.