ATT&CKReferencesNCC Group APT15 Alive and Strong

NCC Group APT15 Alive and Strong

Smallridge, R. (2018, March 10). APT15 is alive and strong: An analysis of RoyalCli and RoyalDNS. Retrieved April 4, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples23

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupKe3chang

Ke3chang has dumped credentials, including by using Mimikatz.

T1003.002
Security Account Manager
GroupKe3chang

Ke3chang has dumped credentials, including by using gsecdump.

T1003.004
LSA Secrets
GroupKe3chang

Ke3chang has dumped credentials, including by using gsecdump.

T1016
System Network Configuration Discovery
GroupKe3chang

Ke3chang has performed local network configuration discovery using ipconfig.

T1018
Remote System Discovery
GroupKe3chang

Ke3chang has used network scanning and enumeration tools, including Ping.

T1021.002
SMB/Windows Admin Shares
GroupKe3chang

Ke3chang actors have been known to copy files to the network shares of other computers to move laterally.

T1049
System Network Connections Discovery
GroupKe3chang

Ke3chang performs local network connection discovery using netstat.

T1056.001
Keylogging
GroupKe3chang

Ke3chang has used keyloggers.

T1057
Process Discovery
GroupKe3chang

Ke3chang performs process discovery using tasklist commands.

T1059
Command and Scripting Interpreter
GroupKe3chang

Malware used by Ke3chang can run commands on the command-line interface.

T1059.003
Windows Command Shell
GroupKe3chang

Ke3chang has used batch scripts in its malware to install persistence mechanisms.

T1071.001
Web Protocols
GroupKe3chang

Ke3chang malware including RoyalCli and BS2005 have communicated over HTTP with the C2 server through Internet Explorer (IE) by using the COM interface IWebBrowser2.

T1071.004
DNS
GroupKe3chang

Ke3chang malware RoyalDNS has used DNS for C2.

T1082
System Information Discovery
GroupKe3chang

Ke3chang performs operating system information discovery using systeminfo and has used implants to identify the system language and computer name.

T1114.002
Remote Email Collection
GroupKe3chang

Ke3chang has used compromised credentials and a .NET tool to dump data from Microsoft Exchange mailboxes.

T1133
External Remote Services
GroupKe3chang

Ke3chang has gained access through VPNs including with compromised accounts and stolen VPN certificates.

T1213.002
Sharepoint
GroupKe3chang

Ke3chang used a SharePoint enumeration and data dumping tool known as spwebmember.

T1213.002
Sharepoint
Toolspwebmember

spwebmember is used to enumerate and dump information from Microsoft SharePoint.

T1543.003
Windows Service
GroupKe3chang

Ke3chang backdoor RoyalDNS established persistence through adding a service called Nwsapagent.

T1547.001
Registry Run Keys / Startup Folder
GroupKe3chang

Several Ke3chang backdoors achieved persistence by adding a Run key.

T1558.001
Golden Ticket
GroupKe3chang

Ke3chang has used Mimikatz to generate Kerberos golden tickets.

T1569.002
Service Execution
GroupKe3chang

Ke3chang has used a tool known as RemoteExec (similar to PsExec) to remotely execute batch scripts and binaries.

T1588.002
Tool
GroupKe3chang

Ke3chang has obtained and used tools such as Mimikatz.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.