ATT&CKReferencesUnit 42 Tropic Trooper Nov 2016

Unit 42 Tropic Trooper Nov 2016

Ray, V. (2016, November 22). Tropic Trooper Targets Taiwanese Government and Fossil Fuel Provider With Poison Ivy. Retrieved November 9, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples7

TechniqueUsed byProcedure example
T1057
Process Discovery
GroupTropic Trooper

Tropic Trooper is capable of enumerating the running processes on the system using pslist.

T1140
Deobfuscate/Decode Files or Information
GroupTropic Trooper

Tropic Trooper used shellcode with an XOR algorithm to decrypt a payload. Tropic Trooper also decrypted image files which contained a payload.

T1203
Exploitation for Client Execution
GroupTropic Trooper

Tropic Trooper has executed commands through Microsoft security vulnerabilities, including CVE-2017-11882, CVE-2018-0802, and CVE-2012-0158.

T1221
Template Injection
GroupTropic Trooper

Tropic Trooper delivered malicious documents with the XLSX extension, typically used by OpenXML documents, but the file itself was actually an OLE (XLS) document.

T1518.001
Security Software Discovery
GroupTropic Trooper

Tropic Trooper can search for anti-virus software running on the system.

T1547.004
Winlogon Helper DLL
GroupTropic Trooper

Tropic Trooper has created the Registry key HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell and sets the value to establish persistence.

T1566.001
Spearphishing Attachment
GroupTropic Trooper

Tropic Trooper sent spearphishing emails that contained malicious Microsoft Office and fake installer file attachments.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.