ATT&CKReferencesMicrosoft Iranian Threat Actor Trends November 2021

Microsoft Iranian Threat Actor Trends November 2021

MSTIC. (2021, November 16). Evolving trends in Iranian threat actor activity – MSTIC presentation at CyberWarCon 2021. Retrieved January 12, 2023.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples20

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupMagic Hound

Magic Hound has stolen domain credentials by dumping LSASS process memory using Task Manager, comsvcs.dll, and from a Microsoft Active Directory Domain Controller using Mimikatz.

T1005
Data from Local System
GroupCURIUM

CURIUM has exfiltrated data from a compromised machine.

T1027.010
Command Obfuscation
GroupMagic Hound

Magic Hound has used base64-encoded commands.

T1027.013
Encrypted/Encoded File
GroupMagic Hound

Magic Hound malware has used base64-encoded files and has also encrypted embedded strings with AES.

T1036.005
Match Legitimate Resource Name or Location
GroupMagic Hound

Magic Hound has used `dllhost.exe` to mask Fast Reverse Proxy (FRP) and `MicrosoftOutLookUpdater.exe` for Plink.

T1036.010
Masquerade Account Name
GroupMagic Hound

Magic Hound has created local accounts named `help` and `DefaultAccount` on compromised machines.

T1059.001
PowerShell
GroupMagic Hound

Magic Hound has used PowerShell for execution and privilege escalation.

T1105
Ingress Tool Transfer
GroupMagic Hound

Magic Hound has downloaded additional code and files from servers onto victims.

T1136.001
Local Account
GroupMagic Hound

Magic Hound has created local accounts named `help` and `DefaultAccount` on compromised machines.

T1190
Exploit Public-Facing Application
GroupMagic Hound

Magic Hound has exploited the Log4j utility (CVE-2021-44228), on-premises MS Exchange servers via "ProxyShell" (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207), and Fortios SSL VPNs (CVE-2018-13379).

T1204.002
Malicious File
GroupCURIUM

CURIUM has lured users into opening malicious files delivered via social media.

T1486
Data Encrypted for Impact
GroupMagic Hound

Magic Hound has used BitLocker and DiskCryptor to encrypt targeted workstations.

T1547.001
Registry Run Keys / Startup Folder
GroupMagic Hound

Magic Hound malware has used Registry Run keys to establish persistence.

T1566.002
Spearphishing Link
GroupMagic Hound

Magic Hound has sent malicious URL links through email to victims. In some cases the URLs were shortened or linked to Word documents with malicious macros that executed PowerShells scripts to download Pupy.

T1566.003
Spearphishing via Service
GroupCURIUM

CURIUM has used social media to deliver malicious files to victims.

T1585.001
Social Media Accounts
GroupCURIUM

CURIUM has established a network of fictitious social media accounts, including on Facebook and LinkedIn, to establish relationships with victims, often posing as an attractive woman.

T1588.002
Tool
GroupMagic Hound

Magic Hound has obtained and used tools like Havij, sqlmap, Metasploit, Mimikatz, and Plink.

T1589.001
Credentials
GroupMagic Hound

Magic Hound gathered credentials from two victims that they then attempted to validate across 75 different websites. Magic Hound has also collected credentials from over 900 Fortinet VPN servers in the US, Europe, and Israel.

T1595.002
Vulnerability Scanning
GroupMagic Hound

Magic Hound has conducted widespread scanning to identify public-facing systems vulnerable to CVE-2021-44228 in Log4j and ProxyShell vulnerabilities; CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065 in on-premises MS Exchange Servers; and CVE-2018-13379 in Fortinet FortiOS SSL VPNs.

T1598.003
Spearphishing Link
GroupMagic Hound

Magic Hound has used SMS and email messages with links designed to steal credentials or track victims.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.