ATT&CKReferencesProofpoint Leviathan Oct 2017

Proofpoint Leviathan Oct 2017

Axel F, Pierre T. (2017, October 16). Leviathan: Espionage actor spearphishes maritime and defense targets. Retrieved February 15, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software2

Campaigns0

None recorded.

Procedure examples34

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareOrz

Orz can gather victim proxy information.

T1016
System Network Configuration Discovery
MalwareNanHaiShu

NanHaiShu can gather information about the victim proxy server.

T1027
Obfuscated Files or Information
MalwareOrz

Some Orz strings are base64 encoded, such as the embedded DLL known as MockDll.

T1027.001
Binary Padding
GroupLeviathan

Leviathan has inserted garbage characters into code, presumably to avoid anti-virus detection.

T1027.013
Encrypted/Encoded File
GroupLeviathan

Leviathan has obfuscated code using base64.

T1027.015
Compression
GroupLeviathan

Leviathan has obfuscated code using gzip compression.

T1047
Windows Management Instrumentation
GroupLeviathan

Leviathan has used WMI for execution.

T1055.012
Process Hollowing
MalwareOrz

Some Orz versions have an embedded DLL known as MockDll that uses process hollowing and Regsvr32 to execute another payload.

T1057
Process Discovery
MalwareOrz

Orz can gather a process list from the victim.

T1059.001
PowerShell
GroupLeviathan

Leviathan has used PowerShell for execution.

T1059.003
Windows Command Shell
MalwareOrz

Orz can execute shell commands. Orz can execute commands with JavaScript.

T1059.005
Visual Basic
GroupLeviathan

Leviathan has used VBScript.

T1070
Indicator Removal
MalwareOrz

Orz can overwrite Registry settings to reduce its visibility on the victim.

T1082
System Information Discovery
MalwareNanHaiShu

NanHaiShu can gather the victim computer name and serial number.

T1082
System Information Discovery
MalwareOrz

Orz can gather the victim OS version and whether it is 64 or 32 bit.

T1083
File and Directory Discovery
MalwareOrz

Orz can gather victim drive information.

T1102.002
Bidirectional Communication
MalwareOrz

Orz has used Technet and Pastebin web pages for command and control.

T1105
Ingress Tool Transfer
GroupLeviathan

Leviathan has downloaded additional scripts and files from adversary-controlled servers.

T1105
Ingress Tool Transfer
MalwareNanHaiShu

NanHaiShu can download additional files from URLs.

T1105
Ingress Tool Transfer
MalwareOrz

Orz can download files onto the victim.

T1112
Modify Registry
MalwareOrz

Orz can perform Registry operations.

T1140
Deobfuscate/Decode Files or Information
GroupLeviathan

Leviathan has used a DLL known as SeDll to decrypt and execute other JavaScript backdoors.

T1203
Exploitation for Client Execution
GroupLeviathan

Leviathan has exploited multiple Microsoft Office and .NET vulnerabilities for execution, including CVE-2017-0199, CVE-2017-8759, and CVE-2017-11882.

T1204.001
Malicious Link
GroupLeviathan

Leviathan has sent spearphishing email links attempting to get a user to click.

T1204.002
Malicious File
GroupLeviathan

Leviathan has sent spearphishing attachments attempting to get a user to click.

T1218.010
Regsvr32
GroupLeviathan

Leviathan has used regsvr32 for execution.

T1218.010
Regsvr32
MalwareOrz

Some Orz versions have an embedded DLL known as MockDll that uses Process Hollowing and regsvr32 to execute another payload.

T1518
Software Discovery
MalwareOrz

Orz can gather the victim's Internet Explorer version.

T1547.001
Registry Run Keys / Startup Folder
GroupLeviathan

Leviathan has used JavaScript to create a shortcut file in the Startup folder that points to its main backdoor.

T1547.009
Shortcut Modification
GroupLeviathan

Leviathan has used JavaScript to create a shortcut file in the Startup folder that points to its main backdoor.

T1566.001
Spearphishing Attachment
GroupLeviathan

Leviathan has sent spearphishing emails with malicious attachments, including .rtf, .doc, and .xls files.

T1566.002
Spearphishing Link
GroupLeviathan

Leviathan has sent spearphishing emails with links, often using a fraudulent lookalike domain and stolen branding.

T1567.002
Exfiltration to Cloud Storage
GroupLeviathan

Leviathan has used an uploader known as LUNCHMONEY that can exfiltrate files to Dropbox.

T1685
Disable or Modify Tools
MalwareNanHaiShu

NanHaiShu can change Internet Explorer settings to reduce warnings about malware activity.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.