Baumgartner, K., Golovkin, M.. (2015, May). The MsnMM Campaigns: The Earliest Naikon APT Campaigns. Retrieved April 10, 2019.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1008 Fallback Channels |
MalwareSslMM | SslMM has a hard-coded primary and backup C2 string. |
| T1008 Fallback Channels |
MalwareWinMM | WinMM is usually configured with primary and backup domains for C2 communications. |
| T1016 System Network Configuration Discovery |
GroupNaikon | Naikon uses commands such as |
| T1016 System Network Configuration Discovery |
MalwareSys10 | Sys10 collects the local IP address of the victim and sends it to the C2. |
| T1033 System Owner/User Discovery |
MalwareSslMM | SslMM sends the logged-on username to its hard-coded C2. |
| T1033 System Owner/User Discovery |
MalwareSys10 | Sys10 collects the account name of the logged-in user and sends it to the C2. |
| T1033 System Owner/User Discovery |
MalwareWinMM | WinMM uses NetUser-GetInfo to identify that it is running under an “Admin” account on the local system. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareSslMM | To establish persistence, SslMM identifies the Start Menu Startup directory and drops a link to its own executable disguised as an “Office Start,” “Yahoo Talk,” “MSN Gaming Z0ne,” or “MSN Talk” shortcut. |
| T1046 Network Service Discovery |
MalwareHDoor | HDoor scans to identify open ports on the victim. |
| T1056.001 Keylogging |
MalwareSslMM | SslMM creates a new thread implementing a keylogging facility using Windows Keyboard Accelerators. |
| T1057 Process Discovery |
MalwareWinMM | WinMM sets a WH_CBT Windows hook to collect information on process creation. |
| T1069.001 Local Groups |
MalwareSys10 | Sys10 collects the group name of the logged-in user and sends it to the C2. |
| T1071.001 Web Protocols |
MalwareWinMM | WinMM uses HTTP for C2. |
| T1071.001 Web Protocols |
MalwareSys10 | Sys10 uses HTTP for C2. |
| T1082 System Information Discovery |
MalwareSys10 | Sys10 collects the computer name, OS versioning information, and OS install date and sends the information to the C2. |
| T1082 System Information Discovery |
MalwareWinMM | WinMM collects the system name, OS version including service pack, and system install date and sends the information to the C2 server. |
| T1082 System Information Discovery |
MalwareSslMM | SslMM sends information to its hard-coded C2, including OS version, service pack information, processor speed, system name, and OS install date. |
| T1083 File and Directory Discovery |
MalwareWinMM | WinMM sets a WH_CBT Windows hook to search for and capture files on the victim. |
| T1134 Access Token Manipulation |
MalwareSslMM | SslMM contains a feature to manipulate process privileges and tokens. |
| T1518.001 Security Software Discovery |
GroupNaikon | Naikon uses commands such as |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareSslMM | To establish persistence, SslMM identifies the Start Menu Startup directory and drops a link to its own executable disguised as an “Office Start,” “Yahoo Talk,” “MSN Gaming Z0ne,” or “MSN Talk” shortcut. |
| T1547.009 Shortcut Modification |
MalwareSslMM | To establish persistence, SslMM identifies the Start Menu Startup directory and drops a link to its own executable disguised as an “Office Start,” “Yahoo Talk,” “MSN Gaming Z0ne,” or “MSN Talk” shortcut. |
| T1573.001 Symmetric Cryptography |
MalwareSys10 | Sys10 uses an XOR 0x1 loop to encrypt its C2 domain. |
| T1685 Disable or Modify Tools |
MalwareHDoor | HDoor kills anti-virus found on the victim. |
| T1685 Disable or Modify Tools |
MalwareSslMM | SslMM identifies and kills anti-malware processes. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.