Smallridge, R. (2018, March 10). APT15 is alive and strong: An analysis of RoyalCli and RoyalDNS. Retrieved April 4, 2018.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupKe3chang | Ke3chang has dumped credentials, including by using Mimikatz. |
| T1003.002 Security Account Manager |
GroupKe3chang | Ke3chang has dumped credentials, including by using gsecdump. |
| T1003.004 LSA Secrets |
GroupKe3chang | Ke3chang has dumped credentials, including by using gsecdump. |
| T1016 System Network Configuration Discovery |
GroupKe3chang | Ke3chang has performed local network configuration discovery using |
| T1018 Remote System Discovery |
GroupKe3chang | Ke3chang has used network scanning and enumeration tools, including Ping. |
| T1021.002 SMB/Windows Admin Shares |
GroupKe3chang | Ke3chang actors have been known to copy files to the network shares of other computers to move laterally. |
| T1049 System Network Connections Discovery |
GroupKe3chang | Ke3chang performs local network connection discovery using |
| T1056.001 Keylogging |
GroupKe3chang | Ke3chang has used keyloggers. |
| T1057 Process Discovery |
GroupKe3chang | Ke3chang performs process discovery using |
| T1059 Command and Scripting Interpreter |
GroupKe3chang | Malware used by Ke3chang can run commands on the command-line interface. |
| T1059.003 Windows Command Shell |
GroupKe3chang | Ke3chang has used batch scripts in its malware to install persistence mechanisms. |
| T1071.001 Web Protocols |
GroupKe3chang | Ke3chang malware including RoyalCli and BS2005 have communicated over HTTP with the C2 server through Internet Explorer (IE) by using the COM interface IWebBrowser2. |
| T1071.004 DNS |
GroupKe3chang | Ke3chang malware RoyalDNS has used DNS for C2. |
| T1082 System Information Discovery |
GroupKe3chang | Ke3chang performs operating system information discovery using |
| T1114.002 Remote Email Collection |
GroupKe3chang | Ke3chang has used compromised credentials and a .NET tool to dump data from Microsoft Exchange mailboxes. |
| T1133 External Remote Services |
GroupKe3chang | Ke3chang has gained access through VPNs including with compromised accounts and stolen VPN certificates. |
| T1213.002 Sharepoint |
GroupKe3chang | Ke3chang used a SharePoint enumeration and data dumping tool known as spwebmember. |
| T1213.002 Sharepoint |
Toolspwebmember | spwebmember is used to enumerate and dump information from Microsoft SharePoint. |
| T1543.003 Windows Service |
GroupKe3chang | Ke3chang backdoor RoyalDNS established persistence through adding a service called |
| T1547.001 Registry Run Keys / Startup Folder |
GroupKe3chang | Several Ke3chang backdoors achieved persistence by adding a Run key. |
| T1558.001 Golden Ticket |
GroupKe3chang | Ke3chang has used Mimikatz to generate Kerberos golden tickets. |
| T1569.002 Service Execution |
GroupKe3chang | Ke3chang has used a tool known as RemoteExec (similar to PsExec) to remotely execute batch scripts and binaries. |
| T1588.002 Tool |
GroupKe3chang |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.