ATT&CKReferencesBaumgartner Naikon 2015

Baumgartner Naikon 2015

Baumgartner, K., Golovkin, M.. (2015, May). The MsnMM Campaigns: The Earliest Naikon APT Campaigns. Retrieved April 10, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software4

Campaigns0

None recorded.

Procedure examples25

TechniqueUsed byProcedure example
T1008
Fallback Channels
MalwareSslMM

SslMM has a hard-coded primary and backup C2 string.

T1008
Fallback Channels
MalwareWinMM

WinMM is usually configured with primary and backup domains for C2 communications.

T1016
System Network Configuration Discovery
GroupNaikon

Naikon uses commands such as netsh interface show to discover network interface settings.

T1016
System Network Configuration Discovery
MalwareSys10

Sys10 collects the local IP address of the victim and sends it to the C2.

T1033
System Owner/User Discovery
MalwareSslMM

SslMM sends the logged-on username to its hard-coded C2.

T1033
System Owner/User Discovery
MalwareSys10

Sys10 collects the account name of the logged-in user and sends it to the C2.

T1033
System Owner/User Discovery
MalwareWinMM

WinMM uses NetUser-GetInfo to identify that it is running under an “Admin” account on the local system.

T1036.005
Match Legitimate Resource Name or Location
MalwareSslMM

To establish persistence, SslMM identifies the Start Menu Startup directory and drops a link to its own executable disguised as an “Office Start,” “Yahoo Talk,” “MSN Gaming Z0ne,” or “MSN Talk” shortcut.

T1046
Network Service Discovery
MalwareHDoor

HDoor scans to identify open ports on the victim.

T1056.001
Keylogging
MalwareSslMM

SslMM creates a new thread implementing a keylogging facility using Windows Keyboard Accelerators.

T1057
Process Discovery
MalwareWinMM

WinMM sets a WH_CBT Windows hook to collect information on process creation.

T1069.001
Local Groups
MalwareSys10

Sys10 collects the group name of the logged-in user and sends it to the C2.

T1071.001
Web Protocols
MalwareWinMM

WinMM uses HTTP for C2.

T1071.001
Web Protocols
MalwareSys10

Sys10 uses HTTP for C2.

T1082
System Information Discovery
MalwareSys10

Sys10 collects the computer name, OS versioning information, and OS install date and sends the information to the C2.

T1082
System Information Discovery
MalwareWinMM

WinMM collects the system name, OS version including service pack, and system install date and sends the information to the C2 server.

T1082
System Information Discovery
MalwareSslMM

SslMM sends information to its hard-coded C2, including OS version, service pack information, processor speed, system name, and OS install date.

T1083
File and Directory Discovery
MalwareWinMM

WinMM sets a WH_CBT Windows hook to search for and capture files on the victim.

T1134
Access Token Manipulation
MalwareSslMM

SslMM contains a feature to manipulate process privileges and tokens.

T1518.001
Security Software Discovery
GroupNaikon

Naikon uses commands such as netsh advfirewall firewall to discover local firewall settings.

T1547.001
Registry Run Keys / Startup Folder
MalwareSslMM

To establish persistence, SslMM identifies the Start Menu Startup directory and drops a link to its own executable disguised as an “Office Start,” “Yahoo Talk,” “MSN Gaming Z0ne,” or “MSN Talk” shortcut.

T1547.009
Shortcut Modification
MalwareSslMM

To establish persistence, SslMM identifies the Start Menu Startup directory and drops a link to its own executable disguised as an “Office Start,” “Yahoo Talk,” “MSN Gaming Z0ne,” or “MSN Talk” shortcut.

T1573.001
Symmetric Cryptography
MalwareSys10

Sys10 uses an XOR 0x1 loop to encrypt its C2 domain.

T1685
Disable or Modify Tools
MalwareHDoor

HDoor kills anti-virus found on the victim.

T1685
Disable or Modify Tools
MalwareSslMM

SslMM identifies and kills anti-malware processes.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.