ATT&CKReferencesMicrosoft Actinium February 2022

Microsoft Actinium February 2022

Microsoft Threat Intelligence Center. (2022, February 4). ACTINIUM targets Ukrainian organizations. Retrieved February 18, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software2

Campaigns0

None recorded.

Procedure examples27

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareQuietSieve

QuietSieve can collect files from a compromised host.

T1016.001
Internet Connection Discovery
MalwareQuietSieve

QuietSieve can check C2 connectivity with a `ping` to 8.8.8.8 (Google public DNS).

T1021.005
VNC
GroupGamaredon Group

Gamaredon Group has used VNC tools, including UltraVNC, to remotely interact with compromised hosts.

T1027.007
Dynamic API Resolution
MalwarePteranodon

Pteranodon can use a dynamic Windows hashing algorithm to map API components.

T1027.010
Command Obfuscation
MalwarePowerPunch

PowerPunch can use Base64-encoded scripts.

T1027.010
Command Obfuscation
GroupGamaredon Group

Gamaredon Group has used obfuscated or encrypted scripts.

T1053.005
Scheduled Task
GroupGamaredon Group

Gamaredon Group has created scheduled tasks to launch executables after a designated number of minutes have passed.

T1059.001
PowerShell
MalwarePowerPunch

PowerPunch has the ability to execute through PowerShell.

T1059.001
PowerShell
GroupGamaredon Group

Gamaredon Group has used obfuscated PowerShell scripts for staging. Additionally, (LinkById : G0047) has used PowerShell based tools later in its attack chain. Additionally, Gamaredon Group has used the PowerShell cmdlet `Get-Command` to download and execute the next stage payload.

T1059.005
Visual Basic
GroupGamaredon Group

Gamaredon Group has embedded malicious macros in document templates, which executed VBScript. Gamaredon Group has also delivered Microsoft Outlook VBA projects with embedded macros. Additionally, Gamaredon Group has executed VBScript files using wscript.exe.

T1071.001
Web Protocols
MalwareQuietSieve

QuietSieve can use HTTPS in C2 communications.

T1083
File and Directory Discovery
MalwareQuietSieve

QuietSieve can search files on the target host by extension, including doc, docx, xls, rtf, odt, txt, jpg, pdf, rar, zip, and 7z.

T1105
Ingress Tool Transfer
GroupGamaredon Group

Gamaredon Group has downloaded additional malware and tools onto a compromised host. For example, Gamaredon Group uses a backdoor script to retrieve and decode additional payloads once in victim environments.

T1105
Ingress Tool Transfer
MalwarePowerPunch

PowerPunch can download payloads from adversary infrastructure.

T1105
Ingress Tool Transfer
MalwareQuietSieve

QuietSieve can download and execute payloads on a target host.

T1106
Native API
MalwarePteranodon

Pteranodon has used various API calls.

T1113
Screen Capture
MalwareQuietSieve

QuietSieve has taken screenshots every five minutes and saved them to the user's local Application Data folder under `Temp\SymbolSourceSymbols\icons` or `Temp\ModeAuto\icons`.

T1120
Peripheral Device Discovery
MalwareQuietSieve

QuietSieve can identify and search removable drives for specific file name extensions.

T1135
Network Share Discovery
MalwareQuietSieve

QuietSieve can identify and search networked drives for specific file name extensions.

T1140
Deobfuscate/Decode Files or Information
MalwarePteranodon

Pteranodon can decrypt encrypted data strings prior to using them.

T1204.002
Malicious File
GroupGamaredon Group

Gamaredon Group has attempted to get users to click on Office attachments with malicious macros embedded. Gamaredon Group has also attempted to get users to click on thematically named files.

T1221
Template Injection
GroupGamaredon Group

Gamaredon Group has used DOCX files to download malicious DOT document templates and has used RTF template injection to download malicious payloads. Gamaredon Group can also inject malicious macros or remote templates into documents already present on compromised systems.

T1480.001
Environmental Keying
MalwarePowerPunch

PowerPunch can use the volume serial number from a target host to generate a unique XOR key for the next stage payload.

T1564.003
Hidden Window
MalwareQuietSieve

QuietSieve has the ability to execute payloads in a hidden window.

T1566.001
Spearphishing Attachment
GroupGamaredon Group

Gamaredon Group has delivered spearphishing emails with malicious attachments to targets. Additionally, Gamaredon Group has distributed malicious LNK files compressed in ZIP archives.

T1583.001
Domains
GroupGamaredon Group

Gamaredon Group has registered multiple domains to facilitate payload staging and C2.

T1608.001
Upload Malware
GroupGamaredon Group

Gamaredon Group has registered domains to stage payloads.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.