ATT&CKReferencesUnit 42 QUADAGENT July 2018

Unit 42 QUADAGENT July 2018

Lee, B., Falcone, R. (2018, July 25). OilRig Targets Technology Service Provider and Government Agency with QUADAGENT. Retrieved August 9, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples24

TechniqueUsed byProcedure example
T1008
Fallback Channels
MalwareQUADAGENT

QUADAGENT uses multiple protocols (HTTPS, HTTP, DNS) for its C2 server as fallback channels if communication with one is unsuccessful.

T1012
Query Registry
MalwareQUADAGENT

QUADAGENT checks if a value exists within a Registry key in the HKCU hive whose name is the same as the scheduled task it has created.

T1016
System Network Configuration Discovery
MalwareQUADAGENT

QUADAGENT gathers the current domain the victim system belongs to.

T1027.010
Command Obfuscation
MalwareQUADAGENT

QUADAGENT was likely obfuscated using `Invoke-Obfuscation`.

T1027.011
Fileless Storage
MalwareQUADAGENT

QUADAGENT stores a session identifier unique to the compromised system as well as a pre-shared key used for encrypting and decrypting C2 communications within a Registry key (such as `HKCU\Office365DCOMCheck`) in the `HKCU` hive.

T1027.013
Encrypted/Encoded File
GroupOilRig

OilRig has encrypted and encoded data in its malware, including by using base64.

T1033
System Owner/User Discovery
MalwareQUADAGENT

QUADAGENT gathers the victim username.

T1036.005
Match Legitimate Resource Name or Location
MalwareQUADAGENT

QUADAGENT used the PowerShell filenames Office365DCOMCheck.ps1 and SystemDiskClean.ps1.

T1053.005
Scheduled Task
GroupOilRig

OilRig has created scheduled tasks that run a VBScript to execute a payload on victim machines.

T1053.005
Scheduled Task
MalwareQUADAGENT

QUADAGENT creates a scheduled task to maintain persistence on the victim’s machine.

T1059
Command and Scripting Interpreter
GroupOilRig

OilRig has used various types of scripting for execution.

T1059.001
PowerShell
MalwareQUADAGENT

QUADAGENT uses PowerShell scripts for execution.

T1059.003
Windows Command Shell
GroupOilRig

OilRig has used macros to deliver malware such as QUADAGENT and OopsIE. OilRig has used batch scripts.

T1059.003
Windows Command Shell
MalwareQUADAGENT

QUADAGENT uses cmd.exe to execute scripts and commands on the victim’s machine.

T1059.005
Visual Basic
MalwareQUADAGENT

QUADAGENT uses VBScripts.

T1070.004
File Deletion
MalwareQUADAGENT

QUADAGENT has a command to delete its Registry key and scheduled task.

T1071.001
Web Protocols
MalwareQUADAGENT

QUADAGENT uses HTTPS and HTTP for C2 communications.

T1071.004
DNS
MalwareQUADAGENT

QUADAGENT uses DNS for C2 communications.

T1112
Modify Registry
MalwareQUADAGENT

QUADAGENT modifies an HKCU Registry key to store a session identifier unique to the compromised system as well as a pre-shared key used for encrypting and decrypting C2 communications.

T1132.001
Standard Encoding
MalwareQUADAGENT

QUADAGENT encodes C2 communications with base64.

T1140
Deobfuscate/Decode Files or Information
MalwareQUADAGENT

QUADAGENT uses AES and a preshared key to decrypt the custom Base64 routine used to encode strings and scripts.

T1204.001
Malicious Link
GroupOilRig

OilRig has delivered malicious links to achieve execution on the target system.

T1204.002
Malicious File
GroupOilRig

OilRig has delivered macro-enabled documents that required targets to click the "enable content" button to execute the payload on the system.

T1566.001
Spearphishing Attachment
GroupOilRig

OilRig has sent spearphising emails with malicious attachments to potential victims using compromised and/or spoofed email accounts.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.