ATT&CKReferencesCheckpoint MosesStaff Nov 2021

Checkpoint MosesStaff Nov 2021

Checkpoint Research. (2021, November 15). Uncovering MosesStaff techniques: Ideology over Money. Retrieved August 11, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software2

Campaigns0

None recorded.

Procedure examples31

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
GroupMoses Staff

Moses Staff has collected the domain name of a compromised network.

T1021.002
SMB/Windows Admin Shares
GroupMoses Staff

Moses Staff has used batch scripts that can enable SMB on a compromised host.

T1027.013
Encrypted/Encoded File
MalwarePyDCrypt

PyDCrypt has been compiled and encrypted with PyInstaller, specifically using the --key flag during the build phase.

T1027.013
Encrypted/Encoded File
GroupMoses Staff

Moses Staff has used obfuscated web shells in their operations.

T1027.013
Encrypted/Encoded File
MalwareDCSrv

DCSrv's configuration is encrypted.

T1033
System Owner/User Discovery
MalwarePyDCrypt

PyDCrypt has probed victim machines with whoami and has collected the username from the machine.

T1036.004
Masquerade Task or Service
MalwareDCSrv

DCSrv has masqueraded its service as a legitimate svchost.exe process.

T1036.005
Match Legitimate Resource Name or Location
MalwarePyDCrypt

PyDCrypt has dropped DCSrv under the `svchost.exe` name to disk.

T1047
Windows Management Instrumentation
MalwarePyDCrypt

PyDCrypt has attempted to execute with WMIC.

T1049
System Network Connections Discovery
MalwarePyDCrypt

PyDCrypt has used netsh to find RPC connections on remote machines.

T1059.001
PowerShell
MalwarePyDCrypt

PyDCrypt has attempted to execute with PowerShell.

T1059.003
Windows Command Shell
MalwarePyDCrypt

PyDCrypt has used `cmd.exe` for execution.

T1059.006
Python
MalwarePyDCrypt

PyDCrypt, along with its functions, is written in Python.

T1070.004
File Deletion
MalwarePyDCrypt

PyDCrypt will remove all created artifacts such as dropped executables.

T1082
System Information Discovery
GroupMoses Staff

Moses Staff collected information about the infected host, including the machine names and OS architecture.

T1087.001
Local Account
GroupMoses Staff

Moses Staff has collected the administrator username from a compromised host.

T1105
Ingress Tool Transfer
GroupMoses Staff

Moses Staff has downloaded and installed web shells to following path C:\inetpub\wwwroot\aspnet_client\system_web\IISpool.aspx.

T1106
Native API
MalwareDCSrv

DCSrv has used various Windows API functions, including `DeviceIoControl`, as part of its encryption process.

T1112
Modify Registry
MalwareDCSrv

DCSrv has created Registry keys for persistence.

T1124
System Time Discovery
MalwareDCSrv

DCSrv can compare the current time on an infected host with a configuration value to determine when to start the encryption process.

T1140
Deobfuscate/Decode Files or Information
MalwarePyDCrypt

PyDCrypt has decrypted and dropped the DCSrv payload to disk.

T1190
Exploit Public-Facing Application
GroupMoses Staff

Moses Staff has exploited known vulnerabilities in public-facing infrastructure such as Microsoft Exchange Servers.

T1486
Data Encrypted for Impact
MalwareDCSrv

DCSrv has encrypted drives using the core encryption mechanism from DiskCryptor.

T1505.003
Web Shell
GroupMoses Staff

Moses Staff has dropped a web shell onto a compromised system.

T1529
System Shutdown/Reboot
MalwareDCSrv

DCSrv has a function to sleep for two hours before rebooting the system.

T1543.003
Windows Service
MalwareDCSrv

DCSrv has created new services for persistence by modifying the Registry.

T1553.002
Code Signing
GroupMoses Staff

Moses Staff has used signed drivers from an open source tool called DiskCryptor to evade detection.

T1587.001
Malware
GroupMoses Staff

Moses Staff has built malware, such as DCSrv and PyDCrypt, for targeting victims' machines.

T1588.002
Tool
GroupMoses Staff

Moses Staff has used the commercial tool DiskCryptor.

T1686
Disable or Modify System Firewall
MalwarePyDCrypt

PyDCrypt has modified firewall rules to allow incoming SMB, NetBIOS, and RPC connections using `netsh.exe` on remote machines.

T1686.003
Windows Host Firewall
GroupMoses Staff

Moses Staff has used batch scripts that can disable the Windows firewall on specific remote machines.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.