ATT&CKReferencesCrowdstrike TELCO BPO Campaign December 2022

Crowdstrike TELCO BPO Campaign December 2022

Parisi, T. (2022, December 2). Not a SIMulation: CrowdStrike Investigations Reveal Intrusion Campaign Targeting Telco and BPO Companies. Retrieved June 30, 2023.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns1

Procedure examples28

TechniqueUsed byProcedure example
T1003.006
DCSync
CampaignC0027

During C0027, Scattered Spider performed domain replication.

T1021.007
Cloud Services
CampaignC0027

During C0027, Scattered Spider used compromised Azure credentials for credential theft activity and lateral movement to on-premises systems.

T1046
Network Service Discovery
CampaignC0027

During C0027, used RustScan to scan for open ports on targeted ESXi appliances.

T1047
Windows Management Instrumentation
CampaignC0027

During C0027, Scattered Spider used Windows Management Instrumentation (WMI) to move laterally via Impacket.

T1069.003
Cloud Groups
CampaignC0027

During C0027, Scattered Spider accessed Azure AD to download bulk lists of group members and their Active Directory attributes.

T1078.004
Cloud Accounts
CampaignC0027

During C0027, Scattered Spider leveraged compromised credentials from victim users to authenticate to Azure tenants.

T1087.003
Email Account
CampaignC0027

During C0027, Scattered Spider accessed Azure AD to identify email addresses.

T1087.004
Cloud Account
CampaignC0027

During C0027, Scattered Spider accessed Azure AD to download bulk lists of group members and to identify privileged users, along with the email addresses and AD attributes.

T1090
Proxy
CampaignC0027

During C0027, Scattered Spider installed the open-source rsocx reverse proxy tool on a targeted ESXi appliance.

T1098.001
Additional Cloud Credentials
CampaignC0027

During C0027, Scattered Spider used aws_consoler to create temporary federated credentials for fake users in order to obfuscate which AWS credential is compromised and enable pivoting from the AWS CLI to console sessions without MFA.

T1098.003
Additional Cloud Roles
CampaignC0027

During C0027, Scattered Spider used IAM manipulation to gain persistence and to assume or elevate privileges.

T1098.005
Device Registration
CampaignC0027

During C0027, Scattered Spider registered devices for MFA to maintain persistence through victims' VPN.

T1102
Web Service
CampaignC0027

During C0027, Scattered Spider downloaded tools from sites including file.io, GitHub, and paste.ee.

T1105
Ingress Tool Transfer
CampaignC0027

During C0027, Scattered Spider downloaded tools using victim organization systems.

T1133
External Remote Services
CampaignC0027

During C0027, Scattered Spider used Citrix and VPNs to persist in compromised environments.

T1190
Exploit Public-Facing Application
CampaignC0027

During C0027, Scattered Spider exploited CVE-2021-35464 in the ForgeRock Open Access Management (OpenAM) application server to gain initial access.

T1213.002
Sharepoint
CampaignC0027

During C0027, Scattered Spider accessed victim SharePoint environments to search for VPN and MFA enrollment information, help desk instructions, and new hire guides.

T1219.002
Remote Desktop Software
CampaignC0027

During C0027, Scattered Spider directed victims to run remote monitoring and management (RMM) tools.

T1530
Data from Cloud Storage
CampaignC0027

During C0027, Scattered Spider accessed victim OneDrive environments to search for VPN and MFA enrollment information, help desk instructions, and new hire guides.

T1566.004
Spearphishing Voice
CampaignC0027

During C0027, Scattered Spider impersonated legitimate IT personnel in phone calls to direct victims to download a remote monitoring and management (RMM) tool that would allow the adversary to remotely control their system.

T1572
Protocol Tunneling
CampaignC0027

During C0027, Scattered Spider used SSH tunneling in targeted environments.

T1578.002
Create Cloud Instance
CampaignC0027

During C0027, Scattered Spider used access to the victim's Azure tenant to create Azure VMs.

T1588.002
Tool
CampaignC0027

During C0027, Scattered Spider obtained and used multiple tools including the LINpeas privilege escalation utility, aws_consoler, rsocx reverse proxy, Level RMM tool, and RustScan port scanner.

T1589.001
Credentials
CampaignC0027

During C0027, Scattered Spider sent phishing messages via SMS to steal credentials.

T1598.001
Spearphishing Service
CampaignC0027

During C0027, Scattered Spider sent Telegram messages impersonating IT personnel to harvest credentials.

T1598.004
Spearphishing Voice
CampaignC0027

During C0027, Scattered Spider used phone calls to instruct victims to navigate to credential-harvesting websites.

T1621
Multi-Factor Authentication Request Generation
CampaignC0027

During C0027, Scattered Spider attempted to gain access by continuously sending MFA messages to the victim until they accept the MFA push challenge.

T1684.001
Impersonation
CampaignC0027

During C0027, Scattered Spider impersonated legitimate IT personnel in phone calls and text messages either to direct victims to a credential harvesting site or getting victims to run commercial remote monitoring and management (RMM) tools.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.