Axel F, Pierre T. (2017, October 16). Leviathan: Espionage actor spearphishes maritime and defense targets. Retrieved February 15, 2018.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareOrz | Orz can gather victim proxy information. |
| T1016 System Network Configuration Discovery |
MalwareNanHaiShu | NanHaiShu can gather information about the victim proxy server. |
| T1027 Obfuscated Files or Information |
MalwareOrz | Some Orz strings are base64 encoded, such as the embedded DLL known as MockDll. |
| T1027.001 Binary Padding |
GroupLeviathan | Leviathan has inserted garbage characters into code, presumably to avoid anti-virus detection. |
| T1027.013 Encrypted/Encoded File |
GroupLeviathan | Leviathan has obfuscated code using base64. |
| T1027.015 Compression |
GroupLeviathan | Leviathan has obfuscated code using gzip compression. |
| T1047 Windows Management Instrumentation |
GroupLeviathan | Leviathan has used WMI for execution. |
| T1055.012 Process Hollowing |
MalwareOrz | Some Orz versions have an embedded DLL known as MockDll that uses process hollowing and Regsvr32 to execute another payload. |
| T1057 Process Discovery |
MalwareOrz | Orz can gather a process list from the victim. |
| T1059.001 PowerShell |
GroupLeviathan | Leviathan has used PowerShell for execution. |
| T1059.003 Windows Command Shell |
MalwareOrz | Orz can execute shell commands. Orz can execute commands with JavaScript. |
| T1059.005 Visual Basic |
GroupLeviathan | Leviathan has used VBScript. |
| T1070 Indicator Removal |
MalwareOrz | Orz can overwrite Registry settings to reduce its visibility on the victim. |
| T1082 System Information Discovery |
MalwareNanHaiShu | NanHaiShu can gather the victim computer name and serial number. |
| T1082 System Information Discovery |
MalwareOrz | Orz can gather the victim OS version and whether it is 64 or 32 bit. |
| T1083 File and Directory Discovery |
MalwareOrz | Orz can gather victim drive information. |
| T1102.002 Bidirectional Communication |
MalwareOrz | Orz has used Technet and Pastebin web pages for command and control. |
| T1105 Ingress Tool Transfer |
GroupLeviathan | Leviathan has downloaded additional scripts and files from adversary-controlled servers. |
| T1105 Ingress Tool Transfer |
MalwareNanHaiShu | NanHaiShu can download additional files from URLs. |
| T1105 Ingress Tool Transfer |
MalwareOrz | Orz can download files onto the victim. |
| T1112 Modify Registry |
MalwareOrz | Orz can perform Registry operations. |
| T1140 Deobfuscate/Decode Files or Information |
GroupLeviathan | Leviathan has used a DLL known as SeDll to decrypt and execute other JavaScript backdoors. |
| T1203 Exploitation for Client Execution |
GroupLeviathan | Leviathan has exploited multiple Microsoft Office and .NET vulnerabilities for execution, including CVE-2017-0199, CVE-2017-8759, and CVE-2017-11882. |
| T1204.001 Malicious Link |
GroupLeviathan | Leviathan has sent spearphishing email links attempting to get a user to click. |
| T1204.002 Malicious File |
GroupLeviathan | Leviathan has sent spearphishing attachments attempting to get a user to click. |
| T1218.010 Regsvr32 |
GroupLeviathan | Leviathan has used regsvr32 for execution. |
| T1218.010 Regsvr32 |
MalwareOrz | Some Orz versions have an embedded DLL known as MockDll that uses Process Hollowing and regsvr32 to execute another payload. |
| T1518 Software Discovery |
MalwareOrz | Orz can gather the victim's Internet Explorer version. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupLeviathan | Leviathan has used JavaScript to create a shortcut file in the Startup folder that points to its main backdoor. |
| T1547.009 Shortcut Modification |
GroupLeviathan | Leviathan has used JavaScript to create a shortcut file in the Startup folder that points to its main backdoor. |
| T1566.001 Spearphishing Attachment |
GroupLeviathan | Leviathan has sent spearphishing emails with malicious attachments, including .rtf, .doc, and .xls files. |
| T1566.002 Spearphishing Link |
GroupLeviathan | Leviathan has sent spearphishing emails with links, often using a fraudulent lookalike domain and stolen branding. |
| T1567.002 Exfiltration to Cloud Storage |
GroupLeviathan | Leviathan has used an uploader known as LUNCHMONEY that can exfiltrate files to Dropbox. |
| T1685 Disable or Modify Tools |
MalwareNanHaiShu | NanHaiShu can change Internet Explorer settings to reduce warnings about malware activity. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.