ATT&CKReferencesMicrosoft POLONIUM June 2022

Microsoft POLONIUM June 2022

Microsoft. (2022, June 2). Exposing POLONIUM activity and infrastructure targeting Israeli organizations. Retrieved July 1, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software2

Campaigns0

None recorded.

Procedure examples26

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareCreepyDrive

CreepyDrive can upload files to C2 from victim machines.

T1016
System Network Configuration Discovery
MalwareCreepySnail

CreepySnail can use `getmac` and `Get-NetIPAddress` to enumerate network settings.

T1033
System Owner/User Discovery
MalwareCreepySnail

CreepySnail can execute `getUsername` on compromised systems.

T1041
Exfiltration Over C2 Channel
MalwareCreepySnail

CreepySnail can connect to C2 for data exfiltration.

T1059.001
PowerShell
MalwareCreepySnail

CreepySnail can use PowerShell for execution, including the cmdlets `Invoke-WebRequst` and `Invoke-Expression`.

T1059.001
PowerShell
MalwareCreepyDrive

CreepyDrive can use Powershell for execution, including the cmdlets `Invoke-WebRequest` and `Invoke-Expression`.

T1071.001
Web Protocols
MalwareCreepyDrive

CreepyDrive can use HTTPS for C2 using the Microsoft Graph API.

T1071.001
Web Protocols
MalwareCreepySnail

CreepySnail can use HTTP for C2.

T1078
Valid Accounts
GroupPOLONIUM

POLONIUM has used valid compromised credentials to gain access to victim environments.

T1078.002
Domain Accounts
MalwareCreepySnail

CreepySnail can use stolen credentials to authenticate on target networks.

T1083
File and Directory Discovery
MalwareCreepyDrive

CreepyDrive can specify the local file path to upload files from.

T1090
Proxy
GroupPOLONIUM

POLONIUM has used the AirVPN service for operational activity.

T1090
Proxy
GroupCopyKittens

CopyKittens has used the AirVPN service for operational activity.

T1102.002
Bidirectional Communication
MalwareCreepyDrive

CreepyDrive can use OneDrive for C2.

T1102.002
Bidirectional Communication
GroupHEXANE

HEXANE has used cloud services, including OneDrive, for C2.

T1102.002
Bidirectional Communication
GroupPOLONIUM

POLONIUM has used OneDrive and DropBox for C2.

T1105
Ingress Tool Transfer
MalwareCreepyDrive

CreepyDrive can download files to the compromised host.

T1132.001
Standard Encoding
MalwareCreepySnail

CreepySnail can use Base64 to encode its C2 traffic.

T1199
Trusted Relationship
GroupPOLONIUM

POLONIUM has used compromised credentials from an IT company to target downstream customers including a law firm and aviation company.

T1550.001
Application Access Token
MalwareCreepyDrive

CreepyDrive can use legitimate OAuth refresh tokens to authenticate with OneDrive.

T1567.002
Exfiltration to Cloud Storage
GroupHEXANE

HEXANE has used cloud services, including OneDrive, for data exfiltration.

T1567.002
Exfiltration to Cloud Storage
GroupPOLONIUM

POLONIUM has exfiltrated stolen data to POLONIUM-owned OneDrive and Dropbox accounts.

T1567.002
Exfiltration to Cloud Storage
MalwareCreepyDrive

CreepyDrive can use cloud services including OneDrive for data exfiltration.

T1583.006
Web Services
GroupPOLONIUM

POLONIUM has created and used legitimate Microsoft OneDrive accounts for their operations.

T1588.002
Tool
GroupPOLONIUM

POLONIUM has obtained and used tools such as AirVPN and plink in their operations.

T1588.002
Tool
GroupCopyKittens

CopyKittens has used Metasploit, Empire, and AirVPN for post-exploitation activities.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.