ATT&CKReferencesFireEye APT37 Feb 2018

FireEye APT37 Feb 2018

FireEye. (2018, February 20). APT37 (Reaper): The Overlooked North Korean Actor. Retrieved November 17, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software8

Campaigns0

None recorded.

Procedure examples44

TechniqueUsed byProcedure example
T1005
Data from Local System
GroupAPT37

APT37 has collected data from victims' local systems.

T1007
System Service Discovery
MalwareWINERACK

WINERACK can enumerate services.

T1010
Application Window Discovery
MalwareWINERACK

WINERACK can enumerate active windows.

T1033
System Owner/User Discovery
MalwareWINERACK

WINERACK can gather information on the victim username.

T1033
System Owner/User Discovery
MalwareHAPPYWORK

can collect the victim user name.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwareCORALDECK

CORALDECK has exfiltrated data in HTTP POST headers.

T1056.001
Keylogging
MalwareDOGCALL

DOGCALL is capable of logging keystrokes.

T1057
Process Discovery
MalwarePOORAIM

POORAIM can enumerate processes.

T1057
Process Discovery
MalwareWINERACK

WINERACK can enumerate processes.

T1059
Command and Scripting Interpreter
MalwareWINERACK

WINERACK can create a reverse shell that utilizes statically-linked Wine cmd.exe code to emulate Windows command prompt commands.

T1059.003
Windows Command Shell
GroupAPT37

APT37 has used the command-line interface.

T1082
System Information Discovery
MalwareWINERACK

WINERACK can gather information about the host.

T1082
System Information Discovery
MalwarePOORAIM

POORAIM can identify system information, including battery status.

T1082
System Information Discovery
MalwareSLOWDRIFT

SLOWDRIFT collects and sends system information to its C2.

T1082
System Information Discovery
MalwareKARAE

KARAE can collect system information.

T1082
System Information Discovery
MalwareSHUTTERSPEED

SHUTTERSPEED can collect system information.

T1082
System Information Discovery
MalwareHAPPYWORK

can collect system information, including computer name, system manufacturer, IsDebuggerPresent state, and execution path.

T1083
File and Directory Discovery
MalwareCORALDECK

CORALDECK searches for specified files.

T1083
File and Directory Discovery
MalwareWINERACK

WINERACK can enumerate files and directories.

T1083
File and Directory Discovery
MalwarePOORAIM

POORAIM can conduct file browsing.

T1102.002
Bidirectional Communication
MalwareSLOWDRIFT

SLOWDRIFT uses cloud based services for C2.

T1102.002
Bidirectional Communication
MalwareKARAE

KARAE can use public cloud-based storage providers for command and control.

T1102.002
Bidirectional Communication
GroupAPT37

APT37 leverages social networking sites and cloud platforms (AOL, Twitter, Yandex, Mediafire, pCloud, Dropbox, and Box) for C2.

T1102.002
Bidirectional Communication
MalwarePOORAIM

POORAIM has used AOL Instant Messenger for C2.

T1102.002
Bidirectional Communication
MalwareDOGCALL

DOGCALL is capable of leveraging cloud storage APIs such as Cloud, Box, Dropbox, and Yandex for C2.

T1105
Ingress Tool Transfer
MalwareSHUTTERSPEED

SHUTTERSPEED can download and execute an arbitary executable.

T1105
Ingress Tool Transfer
MalwareSLOWDRIFT

SLOWDRIFT downloads additional payloads.

T1105
Ingress Tool Transfer
MalwareKARAE

KARAE can upload and download files, including second-stage malware.

T1105
Ingress Tool Transfer
GroupAPT37

APT37 has downloaded second stage malware from compromised websites.

T1105
Ingress Tool Transfer
MalwareHAPPYWORK

can download and execute a second-stage payload.

T1113
Screen Capture
MalwareSHUTTERSPEED

SHUTTERSPEED can capture screenshots.

T1113
Screen Capture
MalwareDOGCALL

DOGCALL is capable of capturing screenshots of the victim's machine.

T1113
Screen Capture
MalwarePOORAIM

POORAIM can perform screen capturing.

T1123
Audio Capture
GroupAPT37

APT37 has used an audio capturing utility known as SOUNDWAVE that captures microphone input.

T1189
Drive-by Compromise
MalwareKARAE

KARAE was distributed through torrent file-sharing websites to South Korean victims, using a YouTube video downloader application as a lure.

T1189
Drive-by Compromise
GroupAPT37

APT37 has used strategic web compromises, particularly of South Korean websites, to distribute malware. The group has also used torrent file-sharing sites to more indiscriminately disseminate malware to victims. As part of their compromises, the group has used a Javascript based profiler called RICECURRY to profile a victim's web browser and deliver malicious code accordingly.

T1189
Drive-by Compromise
MalwarePOORAIM

POORAIM has been delivered through compromised sites acting as watering holes.

T1203
Exploitation for Client Execution
GroupAPT37

APT37 has used exploits for Flash Player (CVE-2016-4117, CVE-2018-4878), Word (CVE-2017-0199), Internet Explorer (CVE-2020-1380 and CVE-2020-26411), and Microsoft Edge (CVE-2021-26411) for execution.

T1204.002
Malicious File
GroupAPT37

APT37 has sent spearphishing attachments attempting to get a user to open them.

T1547.001
Registry Run Keys / Startup Folder
GroupAPT37

APT37's has added persistence via the Registry key HKCU\Software\Microsoft\CurrentVersion\Run\.

T1555.003
Credentials from Web Browsers
GroupAPT37

APT37 has used a credential stealer known as ZUMKONG that can harvest usernames and passwords stored in browsers.

T1560.001
Archive via Utility
MalwareCORALDECK

CORALDECK has created password-protected RAR, WinImage, and zip archives to be exfiltrated.

T1561.002
Disk Structure Wipe
GroupAPT37

APT37 has access to destructive malware that is capable of overwriting a machine's Master Boot Record (MBR).

T1566.001
Spearphishing Attachment
GroupAPT37

APT37 delivers malware using spearphishing emails with malicious HWP attachments.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.