Checkpoint Research. (2021, November 15). Uncovering MosesStaff techniques: Ideology over Money. Retrieved August 11, 2022.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
GroupMoses Staff | Moses Staff has collected the domain name of a compromised network. |
| T1021.002 SMB/Windows Admin Shares |
GroupMoses Staff | Moses Staff has used batch scripts that can enable SMB on a compromised host. |
| T1027.013 Encrypted/Encoded File |
MalwarePyDCrypt | PyDCrypt has been compiled and encrypted with PyInstaller, specifically using the --key flag during the build phase. |
| T1027.013 Encrypted/Encoded File |
GroupMoses Staff | Moses Staff has used obfuscated web shells in their operations. |
| T1027.013 Encrypted/Encoded File |
MalwareDCSrv | DCSrv's configuration is encrypted. |
| T1033 System Owner/User Discovery |
MalwarePyDCrypt | PyDCrypt has probed victim machines with |
| T1036.004 Masquerade Task or Service |
MalwareDCSrv | DCSrv has masqueraded its service as a legitimate svchost.exe process. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwarePyDCrypt | PyDCrypt has dropped DCSrv under the `svchost.exe` name to disk. |
| T1047 Windows Management Instrumentation |
MalwarePyDCrypt | PyDCrypt has attempted to execute with WMIC. |
| T1049 System Network Connections Discovery |
MalwarePyDCrypt | PyDCrypt has used netsh to find RPC connections on remote machines. |
| T1059.001 PowerShell |
MalwarePyDCrypt | PyDCrypt has attempted to execute with PowerShell. |
| T1059.003 Windows Command Shell |
MalwarePyDCrypt | PyDCrypt has used `cmd.exe` for execution. |
| T1059.006 Python |
MalwarePyDCrypt | PyDCrypt, along with its functions, is written in Python. |
| T1070.004 File Deletion |
MalwarePyDCrypt | PyDCrypt will remove all created artifacts such as dropped executables. |
| T1082 System Information Discovery |
GroupMoses Staff | Moses Staff collected information about the infected host, including the machine names and OS architecture. |
| T1087.001 Local Account |
GroupMoses Staff | Moses Staff has collected the administrator username from a compromised host. |
| T1105 Ingress Tool Transfer |
GroupMoses Staff | Moses Staff has downloaded and installed web shells to following path |
| T1106 Native API |
MalwareDCSrv | DCSrv has used various Windows API functions, including `DeviceIoControl`, as part of its encryption process. |
| T1112 Modify Registry |
MalwareDCSrv | DCSrv has created Registry keys for persistence. |
| T1124 System Time Discovery |
MalwareDCSrv | DCSrv can compare the current time on an infected host with a configuration value to determine when to start the encryption process. |
| T1140 Deobfuscate/Decode Files or Information |
MalwarePyDCrypt | PyDCrypt has decrypted and dropped the DCSrv payload to disk. |
| T1190 Exploit Public-Facing Application |
GroupMoses Staff | Moses Staff has exploited known vulnerabilities in public-facing infrastructure such as Microsoft Exchange Servers. |
| T1486 Data Encrypted for Impact |
MalwareDCSrv | DCSrv has encrypted drives using the core encryption mechanism from DiskCryptor. |
| T1505.003 Web Shell |
GroupMoses Staff | Moses Staff has dropped a web shell onto a compromised system. |
| T1529 System Shutdown/Reboot |
MalwareDCSrv | DCSrv has a function to sleep for two hours before rebooting the system. |
| T1543.003 Windows Service |
MalwareDCSrv | DCSrv has created new services for persistence by modifying the Registry. |
| T1553.002 Code Signing |
GroupMoses Staff | Moses Staff has used signed drivers from an open source tool called DiskCryptor to evade detection. |
| T1587.001 Malware |
GroupMoses Staff | Moses Staff has built malware, such as DCSrv and PyDCrypt, for targeting victims' machines. |
| T1588.002 Tool |
GroupMoses Staff | Moses Staff has used the commercial tool DiskCryptor. |
| T1686 Disable or Modify System Firewall |
MalwarePyDCrypt | PyDCrypt has modified firewall rules to allow incoming SMB, NetBIOS, and RPC connections using `netsh.exe` on remote machines. |
| T1686.003 Windows Host Firewall |
GroupMoses Staff | Moses Staff has used batch scripts that can disable the Windows firewall on specific remote machines. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.