Scott W. Brady. (2020, October 15). United States vs. Yuriy Sergeyevich Andrienko et al.. Retrieved November 25, 2020.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
GroupSandworm Team | Sandworm Team has exfiltrated internal documents, files, and other data from compromised hosts. |
| T1033 System Owner/User Discovery |
GroupSandworm Team | Sandworm Team has collected the username from a compromised host. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupSandworm Team | Sandworm Team has avoided detection by naming a malicious binary explorer.exe. |
| T1049 System Network Connections Discovery |
GroupSandworm Team | Sandworm Team had gathered user, IP address, and server data related to RDP sessions on a compromised host. It has also accessed network diagram files useful for understanding how a host's network was configured. |
| T1059.001 PowerShell |
GroupSandworm Team | Sandworm Team has used PowerShell scripts to run a credential harvesting tool in memory to evade defenses. |
| T1078.002 Domain Accounts |
GroupSandworm Team | Sandworm Team has used stolen credentials to access administrative accounts within the domain. |
| T1082 System Information Discovery |
GroupSandworm Team | Sandworm Team used a backdoor to enumerate information about the infected system's operating system. |
| T1083 File and Directory Discovery |
MalwareNotPetya | NotPetya searches for files ending with dozens of different file extensions prior to encryption. |
| T1083 File and Directory Discovery |
GroupSandworm Team | Sandworm Team has enumerated files on a compromised host. |
| T1105 Ingress Tool Transfer |
GroupSandworm Team | Sandworm Team has pushed additional malicious tools onto an infected system to steal user credentials, move laterally, and destroy data. |
| T1195.002 Compromise Software Supply Chain |
GroupSandworm Team | Sandworm Team has distributed NotPetya by compromising the legitimate Ukrainian accounting software M.E.Doc and replacing a legitimate software update with a malicious one. |
| T1199 Trusted Relationship |
GroupSandworm Team | Sandworm Team has used dedicated network connections from one victim organization to gain unauthorized access to a separate organization. Additionally, Sandworm Team has accessed Internet service providers and telecommunication entities that provide mobile connectivity. |
| T1204.001 Malicious Link |
GroupSandworm Team | Sandworm Team has tricked unwitting recipients into clicking on malicious hyperlinks within emails crafted to resemble trustworthy senders. |
| T1204.002 Malicious File |
GroupSandworm Team | Sandworm Team has tricked unwitting recipients into clicking on spearphishing attachments and enabling malicious macros embedded within files. |
| T1210 Exploitation of Remote Services |
MalwareNotPetya | NotPetya can use two exploits in SMBv1, EternalBlue and EternalRomance, to spread itself to other remote systems on the network. |
| T1485 Data Destruction |
MalwareOlympic Destroyer | Olympic Destroyer overwrites files locally and on remote shares. |
| T1486 Data Encrypted for Impact |
MalwareNotPetya | NotPetya encrypts user files and disk structures like the MBR with 2048-bit RSA. |
| T1491.002 External Defacement |
GroupSandworm Team | Sandworm Team defaced approximately 15,000 websites belonging to Georgian government, non-government, and private sector organizations in 2019. |
| T1499 Endpoint Denial of Service |
GroupSandworm Team | Sandworm Team temporarily disrupted service to Georgian government, non-government, and private sector websites after compromising a Georgian web hosting provider in 2019. |
| T1518.001 Security Software Discovery |
MalwareNotPetya | NotPetya determines if specific antivirus programs are running on an infected host machine. |
| T1529 System Shutdown/Reboot |
MalwareNotPetya | NotPetya will reboot the system one hour after infection. |
| T1529 System Shutdown/Reboot |
MalwareOlympic Destroyer | Olympic Destroyer will shut down the compromised system after it is done modifying system configuration settings. |
| T1566.001 Spearphishing Attachment |
GroupSandworm Team | Sandworm Team has delivered malicious Microsoft Office and ZIP file attachments via spearphishing emails. |
| T1566.002 Spearphishing Link |
GroupSandworm Team | Sandworm Team has crafted phishing emails containing malicious hyperlinks. |
| T1583.001 Domains |
GroupSandworm Team | Sandworm Team has registered domain names and created URLs that are often designed to mimic or spoof legitimate websites, such as email login pages, online file sharing and storage websites, and password reset pages, while also hosting these items on legitimate, compromised network infrastructure. |
| T1583.004 Server |
GroupSandworm Team | Sandworm Team has leased servers from resellers instead of leasing infrastructure directly from hosting companies to enable its operations. |
| T1585.001 Social Media Accounts |
GroupSandworm Team | Sandworm Team has established social media accounts to disseminate victim internal-only documents and other sensitive data. |
| T1585.002 Email Accounts |
GroupSandworm Team | Sandworm Team has created email accounts that mimic legitimate organizations for its spearphishing operations. |
| T1587.001 Malware |
GroupSandworm Team | Sandworm Team has developed malware for its operations, including malicious mobile applications and destructive malware such as NotPetya and Olympic Destroyer. |
| T1588.002 Tool |
GroupSandworm Team | Sandworm Team has acquired open-source tools for their operations, including Invoke-PSImage, which was used to establish an encrypted channel from a compromised host to Sandworm Team's C2 server in preparation for the 2018 Winter Olympics attack, as well as Impacket and RemoteExec, which were used in their 2022 Prestige operations. Additionally, Sandworm Team has used Empire, Cobalt Strike and PoshC2. |
| T1588.006 Vulnerabilities |
GroupSandworm Team | In 2017, Sandworm Team conducted technical research related to vulnerabilities associated with websites used by the Korean Sport and Olympic Committee, a Korean power company, and a Korean airport. |
| T1589.002 Email Addresses |
GroupSandworm Team | Sandworm Team has obtained valid emails addresses while conducting research against target organizations that were subsequently used in spearphishing campaigns. |
| T1589.003 Employee Names |
GroupSandworm Team | Sandworm Team's research of potential victim organizations included the identification and collection of employee information. |
| T1590.001 Domain Properties |
GroupSandworm Team | Sandworm Team conducted technical reconnaissance of the Parliament of Georgia's official internet domain prior to its 2019 attack. |
| T1591.002 Business Relationships |
GroupSandworm Team | In preparation for its attack against the 2018 Winter Olympics, Sandworm Team conducted online research of partner organizations listed on an official PyeongChang Olympics partnership site. |
| T1592.002 Software |
GroupSandworm Team | Sandworm Team has researched software code to enable supply-chain operations, most notably for the 2017 NotPetya attack. Sandworm Team also collected a list of computers using specific software as part of its targeting efforts. |
| T1593 Search Open Websites/Domains |
GroupSandworm Team | Sandworm Team researched Ukraine's unique legal entity identifier (called an "EDRPOU" number), including running queries on the EDRPOU website, in preparation for the NotPetya attack. Sandworm Team has also researched third-party websites to help it craft credible spearphishing emails. |
| T1594 Search Victim-Owned Websites |
GroupSandworm Team | Sandworm Team has conducted research against potential victim websites as part of its operational planning. |
| T1595.002 Vulnerability Scanning |
GroupSandworm Team | Sandworm Team has scanned network infrastructure for vulnerabilities as part of its operational planning. |
| T1598.003 Spearphishing Link |
GroupSandworm Team | Sandworm Team has crafted spearphishing emails with hyperlinks designed to trick unwitting recipients into revealing their account credentials. |
| T1685.005 Clear Windows Event Logs |
MalwareNotPetya | NotPetya uses |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.