ATT&CKReferencesPalo Alto Gamaredon Feb 2017

Palo Alto Gamaredon Feb 2017

Kasza, A. and Reichel, D. (2017, February 27). The Gamaredon Group Toolset Evolution. Retrieved March 1, 2017.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples19

TechniqueUsed byProcedure example
T1025
Data from Removable Media
GroupGamaredon Group

A Gamaredon Group file stealer has the capability to steal data from newly connected logical volumes on a system, including USB drives.

T1033
System Owner/User Discovery
GroupGamaredon Group

A Gamaredon Group file stealer can gather the victim's username to send to a C2 server.

T1041
Exfiltration Over C2 Channel
MalwarePteranodon

Pteranodon exfiltrates screenshot files to its C2 server.

T1041
Exfiltration Over C2 Channel
GroupGamaredon Group

A Gamaredon Group file stealer can transfer collected files to a hardcoded C2 server.

T1053.005
Scheduled Task
MalwarePteranodon

Pteranodon schedules tasks to invoke its components in order to establish persistence.

T1059.003
Windows Command Shell
GroupGamaredon Group

Gamaredon Group has used various batch scripts to establish C2 and download additional files. Gamaredon Group's backdoor malware has also been written to a batch file.

T1059.003
Windows Command Shell
MalwarePteranodon

Pteranodon can use `cmd.exe` for execution on victim systems.

T1070.004
File Deletion
MalwarePteranodon

Pteranodon can delete files that may interfere with it executing. It also can delete temporary files and itself after the initial script executes.

T1071.001
Web Protocols
MalwarePteranodon

Pteranodon can use HTTP for C2.

T1071.001
Web Protocols
GroupGamaredon Group

Gamaredon Group has used HTTP and HTTPS for C2 communications.

T1074.001
Local Data Staging
MalwarePteranodon

Pteranodon creates various subdirectories under %Temp%\reports\% and copies files to those subdirectories. It also creates a folder at C:\Users\<Username>\AppData\Roaming\Microsoft\store to store screenshot JPEG files.

T1082
System Information Discovery
GroupGamaredon Group

A Gamaredon Group file stealer can gather the victim's computer name and drive serial numbers to send to a C2 server.

T1083
File and Directory Discovery
MalwarePteranodon

Pteranodon identifies files matching certain file extension and copies them to subdirectories it created.

T1105
Ingress Tool Transfer
MalwarePteranodon

Pteranodon can download and execute additional files.

T1105
Ingress Tool Transfer
GroupGamaredon Group

Gamaredon Group has downloaded additional malware and tools onto a compromised host. For example, Gamaredon Group uses a backdoor script to retrieve and decode additional payloads once in victim environments.

T1113
Screen Capture
MalwarePteranodon

Pteranodon can capture screenshots at a configurable interval.

T1120
Peripheral Device Discovery
GroupGamaredon Group

Gamaredon Group tools have contained an application to check performance of USB flash drives. Gamaredon Group has also used malware to scan for removable drives.

T1218.011
Rundll32
MalwarePteranodon

Pteranodon executes functions using rundll32.exe.

T1547.001
Registry Run Keys / Startup Folder
MalwarePteranodon

Pteranodon copies itself to the Startup folder to establish persistence.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.