ATT&CKReferencesFBI FLASH APT39 September 2020

FBI FLASH APT39 September 2020

FBI. (2020, September 17). Indicators of Compromise Associated with Rana Intelligence Computing, also known as Advanced Persistent Threat 39, Chafer, Cadelspy, Remexi, and ITG07. Retrieved December 10, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples26

TechniqueUsed byProcedure example
T1005
Data from Local System
GroupAPT39

APT39 has used various tools to steal files from the compromised host.

T1012
Query Registry
GroupAPT39

APT39 has used various strains of malware to query the Registry.

T1027.013
Encrypted/Encoded File
GroupAPT39

APT39 has used malware to drop encrypted CAB files.

T1036.005
Match Legitimate Resource Name or Location
GroupAPT39

APT39 has used malware disguised as Mozilla Firefox and a tool named mfevtpse.exe to proxy C2 communications, closely mimicking a legitimate McAfee file mfevtps.exe.

T1041
Exfiltration Over C2 Channel
GroupAPT39

APT39 has exfiltrated stolen victim data through C2 communications.

T1053.005
Scheduled Task
GroupAPT39

APT39 has created scheduled tasks for persistence.

T1056
Input Capture
GroupAPT39

APT39 has utilized tools to capture mouse movements.

T1056.001
Keylogging
GroupAPT39

APT39 has used tools for capturing keystrokes.

T1059
Command and Scripting Interpreter
GroupAPT39

APT39 has utilized custom scripts to perform internal reconnaissance.

T1059.005
Visual Basic
GroupAPT39

APT39 has utilized malicious VBS scripts in malware.

T1059.006
Python
GroupAPT39

APT39 has used a command line utility and a network scanner written in python.

T1059.010
AutoHotKey & AutoIT
GroupAPT39

APT39 has utilized AutoIt malware scripts embedded in Microsoft Office documents or malicious links.

T1070.004
File Deletion
GroupAPT39

APT39 has used malware to delete files after they are deployed on a compromised host.

T1071.001
Web Protocols
GroupAPT39

APT39 has used HTTP in communications with C2.

T1074.001
Local Data Staging
GroupAPT39

APT39 has utilized tools to aggregate data prior to exfiltration.

T1083
File and Directory Discovery
GroupAPT39

APT39 has used tools with the ability to search for files on a compromised host.

T1105
Ingress Tool Transfer
GroupAPT39

APT39 has downloaded tools to compromised hosts.

T1113
Screen Capture
GroupAPT39

APT39 has used a screen capture utility to take screenshots on a compromised host.

T1140
Deobfuscate/Decode Files or Information
GroupAPT39

APT39 has used malware to decrypt encrypted CAB files.

T1197
BITS Jobs
GroupAPT39

APT39 has used the BITS protocol to exfiltrate stolen data from a compromised host.

T1204.001
Malicious Link
GroupAPT39

APT39 has sent spearphishing emails in an attempt to lure users to click on a malicious link.

T1204.002
Malicious File
GroupAPT39

APT39 has sent spearphishing emails in an attempt to lure users to click on a malicious attachment.

T1546.010
AppInit DLLs
GroupAPT39

APT39 has used malware to set LoadAppInit_DLLs in the Registry key SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows in order to establish persistence.

T1553.006
Code Signing Policy Modification
GroupAPT39

APT39 has used malware to turn off the RequireSigned feature which ensures only signed DLLs can be run on Windows.

T1566.001
Spearphishing Attachment
GroupAPT39

APT39 leveraged spearphishing emails with malicious attachments to initially compromise victims.

T1566.002
Spearphishing Link
GroupAPT39

APT39 leveraged spearphishing emails with malicious links to initially compromise victims.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.