Kasza, A. and Reichel, D. (2017, February 27). The Gamaredon Group Toolset Evolution. Retrieved March 1, 2017.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1025 Data from Removable Media |
GroupGamaredon Group | A Gamaredon Group file stealer has the capability to steal data from newly connected logical volumes on a system, including USB drives. |
| T1033 System Owner/User Discovery |
GroupGamaredon Group | A Gamaredon Group file stealer can gather the victim's username to send to a C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwarePteranodon | Pteranodon exfiltrates screenshot files to its C2 server. |
| T1041 Exfiltration Over C2 Channel |
GroupGamaredon Group | A Gamaredon Group file stealer can transfer collected files to a hardcoded C2 server. |
| T1053.005 Scheduled Task |
MalwarePteranodon | Pteranodon schedules tasks to invoke its components in order to establish persistence. |
| T1059.003 Windows Command Shell |
GroupGamaredon Group | Gamaredon Group has used various batch scripts to establish C2 and download additional files. Gamaredon Group's backdoor malware has also been written to a batch file. |
| T1059.003 Windows Command Shell |
MalwarePteranodon | Pteranodon can use `cmd.exe` for execution on victim systems. |
| T1070.004 File Deletion |
MalwarePteranodon | Pteranodon can delete files that may interfere with it executing. It also can delete temporary files and itself after the initial script executes. |
| T1071.001 Web Protocols |
MalwarePteranodon | Pteranodon can use HTTP for C2. |
| T1071.001 Web Protocols |
GroupGamaredon Group | Gamaredon Group has used HTTP and HTTPS for C2 communications. |
| T1074.001 Local Data Staging |
MalwarePteranodon | Pteranodon creates various subdirectories under |
| T1082 System Information Discovery |
GroupGamaredon Group | A Gamaredon Group file stealer can gather the victim's computer name and drive serial numbers to send to a C2 server. |
| T1083 File and Directory Discovery |
MalwarePteranodon | Pteranodon identifies files matching certain file extension and copies them to subdirectories it created. |
| T1105 Ingress Tool Transfer |
MalwarePteranodon | Pteranodon can download and execute additional files. |
| T1105 Ingress Tool Transfer |
GroupGamaredon Group | Gamaredon Group has downloaded additional malware and tools onto a compromised host. For example, Gamaredon Group uses a backdoor script to retrieve and decode additional payloads once in victim environments. |
| T1113 Screen Capture |
MalwarePteranodon | Pteranodon can capture screenshots at a configurable interval. |
| T1120 Peripheral Device Discovery |
GroupGamaredon Group | Gamaredon Group tools have contained an application to check performance of USB flash drives. Gamaredon Group has also used malware to scan for removable drives. |
| T1218.011 Rundll32 |
MalwarePteranodon | Pteranodon executes functions using rundll32.exe. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwarePteranodon | Pteranodon copies itself to the Startup folder to establish persistence. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.