MSTIC. (2021, December 6). NICKEL targeting government organizations across Latin America and Europe. Retrieved March 18, 2022.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupKe3chang | Ke3chang has dumped credentials, including by using Mimikatz. |
| T1003.003 NTDS |
GroupKe3chang | Ke3chang has used NTDSDump and other password dumping tools to gather credentials. |
| T1005 Data from Local System |
MalwareNeoichor | Neoichor can upload files from a victim's machine. |
| T1005 Data from Local System |
GroupKe3chang | Ke3chang gathered information and files from local directories for exfiltration. |
| T1016 System Network Configuration Discovery |
MalwareNeoichor | Neoichor can gather the IP address from an infected host. |
| T1016 System Network Configuration Discovery |
GroupKe3chang | Ke3chang has performed local network configuration discovery using |
| T1016.001 Internet Connection Discovery |
MalwareNeoichor | Neoichor can check for Internet connectivity by contacting bing[.]com with the request format `bing[.]com?id=<GetTickCount>`. |
| T1020 Automated Exfiltration |
GroupKe3chang | Ke3chang has performed frequent and scheduled data exfiltration from compromised networks. |
| T1027 Obfuscated Files or Information |
GroupKe3chang | Ke3chang has used Base64-encoded shellcode strings. |
| T1033 System Owner/User Discovery |
MalwareNeoichor | Neoichor can collect the user name from a victim's machine. |
| T1033 System Owner/User Discovery |
GroupKe3chang | Ke3chang has used implants capable of collecting the signed-in username. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupKe3chang | Ke3chang has dropped their malware into legitimate installed software paths including: `C:\ProgramFiles\Realtek\Audio\HDA\AERTSr.exe`, `C:\Program Files (x86)\Foxit Software\Foxit Reader\FoxitRdr64.exe`, `C:\Program Files (x86)\Adobe\Flash Player\AddIns\airappinstaller\airappinstall.exe`, and `C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd64.exe`. |
| T1056.001 Keylogging |
GroupKe3chang | Ke3chang has used keyloggers. |
| T1070 Indicator Removal |
MalwareNeoichor | Neoichor can clear the browser history on a compromised host by changing the `ClearBrowsingHistoryOnExit` value to 1 in the `HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Privacy` Registry key. |
| T1071.001 Web Protocols |
GroupKe3chang | Ke3chang malware including RoyalCli and BS2005 have communicated over HTTP with the C2 server through Internet Explorer (IE) by using the COM interface IWebBrowser2. |
| T1071.001 Web Protocols |
MalwareNeoichor | Neoichor can use HTTP for C2 communications. |
| T1078 Valid Accounts |
GroupKe3chang | Ke3chang has used credential dumpers or stealers to obtain legitimate credentials, which they used to gain access to victim accounts. |
| T1078.004 Cloud Accounts |
GroupKe3chang | Ke3chang has used compromised credentials to sign into victims’ Microsoft 365 accounts. |
| T1082 System Information Discovery |
MalwareNeoichor | Neoichor can collect the OS version and computer name from a compromised host. |
| T1082 System Information Discovery |
GroupKe3chang | Ke3chang performs operating system information discovery using |
| T1083 File and Directory Discovery |
GroupKe3chang | Ke3chang uses command-line interaction to search files and directories. |
| T1105 Ingress Tool Transfer |
GroupKe3chang | Ke3chang has used tools to download files to compromised machines. |
| T1105 Ingress Tool Transfer |
MalwareNeoichor | Neoichor can download additional files onto a compromised host. |
| T1112 Modify Registry |
MalwareNeoichor | Neoichor has the ability to configure browser settings by modifying Registry entries under `HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer`. |
| T1114.002 Remote Email Collection |
GroupKe3chang | Ke3chang has used compromised credentials and a .NET tool to dump data from Microsoft Exchange mailboxes. |
| T1119 Automated Collection |
GroupKe3chang | Ke3chang has performed frequent and scheduled data collection from victim networks. |
| T1133 External Remote Services |
GroupKe3chang | Ke3chang has gained access through VPNs including with compromised accounts and stolen VPN certificates. |
| T1140 Deobfuscate/Decode Files or Information |
GroupKe3chang | Ke3chang has deobfuscated Base64-encoded shellcode strings prior to loading them. |
| T1190 Exploit Public-Facing Application |
GroupKe3chang | Ke3chang has compromised networks by exploiting Internet-facing applications, including vulnerable Microsoft Exchange and SharePoint servers. |
| T1559.001 Component Object Model |
MalwareNeoichor | Neoichor can use the Internet Explorer (IE) COM interface to connect and receive commands from C2. |
| T1560.001 Archive via Utility |
GroupKe3chang | Ke3chang is known to use 7Zip and RAR with passwords to encrypt data prior to exfiltration. |
| T1587.001 Malware |
GroupKe3chang | Ke3chang has developed custom malware that allowed them to maintain persistence on victim networks. |
| T1614.001 System Language Discovery |
GroupKe3chang | Ke3chang has used implants to collect the system language ID of a compromised machine. |
| T1614.001 System Language Discovery |
MalwareNeoichor | Neoichor can identify the system language on a compromised host. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.