ATT&CKReferencesATT Sidewinder January 2021

ATT Sidewinder January 2021

Hegel, T. (2021, January 13). A Global Perspective of the SideWinder APT. Retrieved January 27, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples25

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
GroupSidewinder

Sidewinder has used malware to collect information on network interfaces, including the MAC address.

T1020
Automated Exfiltration
GroupSidewinder

Sidewinder has configured tools to automatically send collected files to attacker controlled servers.

T1027.010
Command Obfuscation
GroupSidewinder

Sidewinder has used base64 encoding for scripts.

T1027.013
Encrypted/Encoded File
GroupSidewinder

Sidewinder has used base64 encoding and ECDH-P256 encryption for payloads.

T1033
System Owner/User Discovery
GroupSidewinder

Sidewinder has used tools to identify the user of a compromised host.

T1057
Process Discovery
GroupSidewinder

Sidewinder has used tools to identify running processes on the victim's machine.

T1059.001
PowerShell
GroupSidewinder

Sidewinder has used PowerShell to drop and execute malware loaders.

T1059.005
Visual Basic
GroupSidewinder

Sidewinder has used VBScript to drop and execute malware loaders.

T1059.007
JavaScript
GroupSidewinder

Sidewinder has used JavaScript to drop and execute malware loaders.

T1071.001
Web Protocols
GroupSidewinder

Sidewinder has used HTTP in C2 communications.

T1074.001
Local Data Staging
GroupSidewinder

Sidewinder has collected stolen files in a temporary folder in preparation for exfiltration.

T1082
System Information Discovery
GroupSidewinder

Sidewinder has used tools to collect the computer name, OS version, installed hotfixes, as well as information regarding the memory and processor on a compromised host.

T1083
File and Directory Discovery
GroupSidewinder

Sidewinder has used malware to collect information on files and directories.

T1105
Ingress Tool Transfer
GroupSidewinder

Sidewinder has used LNK files to download remote files to the victim's network.

T1119
Automated Collection
GroupSidewinder

Sidewinder has used tools to automatically collect system and network configuration information.

T1124
System Time Discovery
GroupSidewinder

Sidewinder has used tools to obtain the current system time.

T1203
Exploitation for Client Execution
GroupSidewinder

Sidewinder has exploited vulnerabilities to gain execution including CVE-2017-11882 and CVE-2020-0674.

T1204.001
Malicious Link
GroupSidewinder

Sidewinder has lured targets to click on malicious links to gain execution in the target environment.

T1204.002
Malicious File
GroupSidewinder

Sidewinder has lured targets to click on malicious files to gain execution in the target environment.

T1518
Software Discovery
GroupSidewinder

Sidewinder has used tools to enumerate software installed on an infected host.

T1566.001
Spearphishing Attachment
GroupSidewinder

Sidewinder has sent e-mails with malicious attachments often crafted for specific targets.

T1566.002
Spearphishing Link
GroupSidewinder

Sidewinder has sent e-mails with malicious links often crafted for specific targets.

T1574.001
DLL
GroupSidewinder

Sidewinder has used DLL side-loading to drop and execute malicious payloads including the hijacking of the legitimate Windows application file rekeywiz.exe.

T1598.002
Spearphishing Attachment
GroupSidewinder

Sidewinder has sent e-mails with malicious attachments that lead victims to credential harvesting websites.

T1598.003
Spearphishing Link
GroupSidewinder

Sidewinder has sent e-mails with malicious links to credential harvesting websites.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.