ATT&CKReferencesMandiant Operation Ke3chang November 2014

Mandiant Operation Ke3chang November 2014

Villeneuve, N., Bennett, J. T., Moran, N., Haq, T., Scott, M., & Geers, K. (2014). OPERATION “KE3CHANG”: Targeted Attacks Against Ministries of Foreign Affairs. Retrieved November 12, 2014.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples20

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupKe3chang

Ke3chang has dumped credentials, including by using Mimikatz.

T1003.002
Security Account Manager
GroupKe3chang

Ke3chang has dumped credentials, including by using gsecdump.

T1003.004
LSA Secrets
GroupKe3chang

Ke3chang has dumped credentials, including by using gsecdump.

T1005
Data from Local System
GroupKe3chang

Ke3chang gathered information and files from local directories for exfiltration.

T1007
System Service Discovery
GroupKe3chang

Ke3chang performs service discovery using net start commands.

T1016
System Network Configuration Discovery
GroupKe3chang

Ke3chang has performed local network configuration discovery using ipconfig.

T1021.002
SMB/Windows Admin Shares
GroupKe3chang

Ke3chang actors have been known to copy files to the network shares of other computers to move laterally.

T1036.002
Right-to-Left Override
GroupKe3chang

Ke3chang has used the right-to-left override character in spearphishing attachment names to trick targets into executing .scr and .exe files.

T1041
Exfiltration Over C2 Channel
GroupKe3chang

Ke3chang transferred compressed and encrypted RAR files containing exfiltration through the established backdoor command and control channel during operations.

T1049
System Network Connections Discovery
GroupKe3chang

Ke3chang performs local network connection discovery using netstat.

T1057
Process Discovery
GroupKe3chang

Ke3chang performs process discovery using tasklist commands.

T1059
Command and Scripting Interpreter
GroupKe3chang

Malware used by Ke3chang can run commands on the command-line interface.

T1069.002
Domain Groups
GroupKe3chang

Ke3chang performs discovery of permission groups net group /domain.

T1082
System Information Discovery
GroupKe3chang

Ke3chang performs operating system information discovery using systeminfo and has used implants to identify the system language and computer name.

T1083
File and Directory Discovery
GroupKe3chang

Ke3chang uses command-line interaction to search files and directories.

T1087.001
Local Account
GroupKe3chang

Ke3chang performs account discovery using commands such as net localgroup administrators and net group "REDACTED" /domain on specific permissions groups.

T1087.002
Domain Account
GroupKe3chang

Ke3chang performs account discovery using commands such as net localgroup administrators and net group "REDACTED" /domain on specific permissions groups.

T1132.001
Standard Encoding
MalwareBS2005

BS2005 uses Base64 encoding for communication in the message body of an HTTP request.

T1560
Archive Collected Data
GroupKe3chang

The Ke3chang group has been known to compress data before exfiltration.

T1560.001
Archive via Utility
GroupKe3chang

Ke3chang is known to use 7Zip and RAR with passwords to encrypt data prior to exfiltration.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.