ATT&CKReferencesTrendMicro Tropic Trooper Mar 2018

TrendMicro Tropic Trooper Mar 2018

Horejsi, J., et al. (2018, March 14). Tropic Trooper’s New Strategy. Retrieved November 9, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples6

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
GroupTropic Trooper

Tropic Trooper has encrypted configuration files.

T1055.001
Dynamic-link Library Injection
GroupTropic Trooper

Tropic Trooper has injected a DLL backdoor into dllhost.exe and svchost.exe.

T1197
BITS Jobs
ToolBITSAdmin

BITSAdmin can be used to create BITS Jobs to launch a malicious process.

T1203
Exploitation for Client Execution
GroupTropic Trooper

Tropic Trooper has executed commands through Microsoft security vulnerabilities, including CVE-2017-11882, CVE-2018-0802, and CVE-2012-0158.

T1564.001
Hidden Files and Directories
GroupTropic Trooper

Tropic Trooper has created a hidden directory under C:\ProgramData\Apple\Updates\ and C:\Users\Public\Documents\Flash\.

T1573.002
Asymmetric Cryptography
GroupTropic Trooper

Tropic Trooper has used SSL to connect to C2 servers.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.