ATT&CKReferencesUS District Court Indictment GRU Unit 74455 October 2020

US District Court Indictment GRU Unit 74455 October 2020

Scott W. Brady. (2020, October 15). United States vs. Yuriy Sergeyevich Andrienko et al.. Retrieved November 25, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software2

Campaigns0

None recorded.

Procedure examples41

TechniqueUsed byProcedure example
T1005
Data from Local System
GroupSandworm Team

Sandworm Team has exfiltrated internal documents, files, and other data from compromised hosts.

T1033
System Owner/User Discovery
GroupSandworm Team

Sandworm Team has collected the username from a compromised host.

T1036.005
Match Legitimate Resource Name or Location
GroupSandworm Team

Sandworm Team has avoided detection by naming a malicious binary explorer.exe.

T1049
System Network Connections Discovery
GroupSandworm Team

Sandworm Team had gathered user, IP address, and server data related to RDP sessions on a compromised host. It has also accessed network diagram files useful for understanding how a host's network was configured.

T1059.001
PowerShell
GroupSandworm Team

Sandworm Team has used PowerShell scripts to run a credential harvesting tool in memory to evade defenses.

T1078.002
Domain Accounts
GroupSandworm Team

Sandworm Team has used stolen credentials to access administrative accounts within the domain.

T1082
System Information Discovery
GroupSandworm Team

Sandworm Team used a backdoor to enumerate information about the infected system's operating system.

T1083
File and Directory Discovery
MalwareNotPetya

NotPetya searches for files ending with dozens of different file extensions prior to encryption.

T1083
File and Directory Discovery
GroupSandworm Team

Sandworm Team has enumerated files on a compromised host.

T1105
Ingress Tool Transfer
GroupSandworm Team

Sandworm Team has pushed additional malicious tools onto an infected system to steal user credentials, move laterally, and destroy data.

T1195.002
Compromise Software Supply Chain
GroupSandworm Team

Sandworm Team has distributed NotPetya by compromising the legitimate Ukrainian accounting software M.E.Doc and replacing a legitimate software update with a malicious one.

T1199
Trusted Relationship
GroupSandworm Team

Sandworm Team has used dedicated network connections from one victim organization to gain unauthorized access to a separate organization. Additionally, Sandworm Team has accessed Internet service providers and telecommunication entities that provide mobile connectivity.

T1204.001
Malicious Link
GroupSandworm Team

Sandworm Team has tricked unwitting recipients into clicking on malicious hyperlinks within emails crafted to resemble trustworthy senders.

T1204.002
Malicious File
GroupSandworm Team

Sandworm Team has tricked unwitting recipients into clicking on spearphishing attachments and enabling malicious macros embedded within files.

T1210
Exploitation of Remote Services
MalwareNotPetya

NotPetya can use two exploits in SMBv1, EternalBlue and EternalRomance, to spread itself to other remote systems on the network.

T1485
Data Destruction
MalwareOlympic Destroyer

Olympic Destroyer overwrites files locally and on remote shares.

T1486
Data Encrypted for Impact
MalwareNotPetya

NotPetya encrypts user files and disk structures like the MBR with 2048-bit RSA.

T1491.002
External Defacement
GroupSandworm Team

Sandworm Team defaced approximately 15,000 websites belonging to Georgian government, non-government, and private sector organizations in 2019.

T1499
Endpoint Denial of Service
GroupSandworm Team

Sandworm Team temporarily disrupted service to Georgian government, non-government, and private sector websites after compromising a Georgian web hosting provider in 2019.

T1518.001
Security Software Discovery
MalwareNotPetya

NotPetya determines if specific antivirus programs are running on an infected host machine.

T1529
System Shutdown/Reboot
MalwareNotPetya

NotPetya will reboot the system one hour after infection.

T1529
System Shutdown/Reboot
MalwareOlympic Destroyer

Olympic Destroyer will shut down the compromised system after it is done modifying system configuration settings.

T1566.001
Spearphishing Attachment
GroupSandworm Team

Sandworm Team has delivered malicious Microsoft Office and ZIP file attachments via spearphishing emails.

T1566.002
Spearphishing Link
GroupSandworm Team

Sandworm Team has crafted phishing emails containing malicious hyperlinks.

T1583.001
Domains
GroupSandworm Team

Sandworm Team has registered domain names and created URLs that are often designed to mimic or spoof legitimate websites, such as email login pages, online file sharing and storage websites, and password reset pages, while also hosting these items on legitimate, compromised network infrastructure.

T1583.004
Server
GroupSandworm Team

Sandworm Team has leased servers from resellers instead of leasing infrastructure directly from hosting companies to enable its operations.

T1585.001
Social Media Accounts
GroupSandworm Team

Sandworm Team has established social media accounts to disseminate victim internal-only documents and other sensitive data.

T1585.002
Email Accounts
GroupSandworm Team

Sandworm Team has created email accounts that mimic legitimate organizations for its spearphishing operations.

T1587.001
Malware
GroupSandworm Team

Sandworm Team has developed malware for its operations, including malicious mobile applications and destructive malware such as NotPetya and Olympic Destroyer.

T1588.002
Tool
GroupSandworm Team

Sandworm Team has acquired open-source tools for their operations, including Invoke-PSImage, which was used to establish an encrypted channel from a compromised host to Sandworm Team's C2 server in preparation for the 2018 Winter Olympics attack, as well as Impacket and RemoteExec, which were used in their 2022 Prestige operations. Additionally, Sandworm Team has used Empire, Cobalt Strike and PoshC2.

T1588.006
Vulnerabilities
GroupSandworm Team

In 2017, Sandworm Team conducted technical research related to vulnerabilities associated with websites used by the Korean Sport and Olympic Committee, a Korean power company, and a Korean airport.

T1589.002
Email Addresses
GroupSandworm Team

Sandworm Team has obtained valid emails addresses while conducting research against target organizations that were subsequently used in spearphishing campaigns.

T1589.003
Employee Names
GroupSandworm Team

Sandworm Team's research of potential victim organizations included the identification and collection of employee information.

T1590.001
Domain Properties
GroupSandworm Team

Sandworm Team conducted technical reconnaissance of the Parliament of Georgia's official internet domain prior to its 2019 attack.

T1591.002
Business Relationships
GroupSandworm Team

In preparation for its attack against the 2018 Winter Olympics, Sandworm Team conducted online research of partner organizations listed on an official PyeongChang Olympics partnership site.

T1592.002
Software
GroupSandworm Team

Sandworm Team has researched software code to enable supply-chain operations, most notably for the 2017 NotPetya attack. Sandworm Team also collected a list of computers using specific software as part of its targeting efforts.

T1593
Search Open Websites/Domains
GroupSandworm Team

Sandworm Team researched Ukraine's unique legal entity identifier (called an "EDRPOU" number), including running queries on the EDRPOU website, in preparation for the NotPetya attack. Sandworm Team has also researched third-party websites to help it craft credible spearphishing emails.

T1594
Search Victim-Owned Websites
GroupSandworm Team

Sandworm Team has conducted research against potential victim websites as part of its operational planning.

T1595.002
Vulnerability Scanning
GroupSandworm Team

Sandworm Team has scanned network infrastructure for vulnerabilities as part of its operational planning.

T1598.003
Spearphishing Link
GroupSandworm Team

Sandworm Team has crafted spearphishing emails with hyperlinks designed to trick unwitting recipients into revealing their account credentials.

T1685.005
Clear Windows Event Logs
MalwareNotPetya

NotPetya uses wevtutil to clear the Windows event logs.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.