ATT&CKReferencesCisco Operation Layover September 2021

Cisco Operation Layover September 2021

Ventura, V. (2021, September 16). Operation Layover: How we tracked an attack on the aviation industry to five years of compromise. Retrieved September 15, 2023.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples15

TechniqueUsed byProcedure example
T1016.001
Internet Connection Discovery
GroupTA2541

TA2541 has run scripts to check internet connectivity from compromised hosts.

T1027.002
Software Packing
GroupTA2541

TA2541 has used a .NET packer to obfuscate malicious files.

T1027.013
Encrypted/Encoded File
GroupTA2541

TA2541 has used compressed and char-encoded scripts in operations.

T1027.015
Compression
GroupTA2541

TA2541 has used compressed and char-encoded scripts in operations.

T1055
Process Injection
GroupTA2541

TA2541 has injected malicious code into legitimate .NET related processes including regsvcs.exe, msbuild.exe, and installutil.exe.

T1055.012
Process Hollowing
GroupTA2541

TA2541 has used process hollowing to execute CyberGate malware.

T1059.005
Visual Basic
GroupTA2541

TA2541 has used VBS files to execute or establish persistence for additional payloads, often using file names consistent with email themes or mimicking system functionality.

T1105
Ingress Tool Transfer
GroupTA2541

TA2541 has used malicious scripts and macros with the ability to download additional payloads.

T1204.002
Malicious File
GroupTA2541

TA2541 has used macro-enabled MS Word documents to lure victims into executing malicious payloads.

T1218.005
Mshta
GroupTA2541

TA2541 has used `mshta` to execute scripts including VBS.

T1566.001
Spearphishing Attachment
GroupTA2541

TA2541 has sent phishing emails with malicious attachments for initial access including MS Word documents.

T1573.002
Asymmetric Cryptography
GroupTA2541

TA2541 has used TLS encrypted C2 communications including for campaigns using AsyncRAT.

T1583.001
Domains
GroupTA2541

TA2541 has registered domains often containing the keywords “kimjoy,” “h0pe,” and “grace,” using domain registrars including Netdorm and No-IP DDNS, and hosting providers including xTom GmbH and Danilenko, Artyom.

T1588.002
Tool
GroupTA2541

TA2541 has used commodity remote access tools.

T1608.001
Upload Malware
GroupTA2541

TA2541 has uploaded malware to various platforms including Google Drive, Pastetext, Sharetext, and GitHub.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.