CISA. (2021, July 19). (AA21-200A) Joint Cybersecurity Advisory – Tactics, Techniques, and Procedures of Indicted APT40 Actors Associated with China’s MSS Hainan State Security Department. Retrieved August 12, 2021.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.003 Steganography |
GroupLeviathan | Leviathan has used steganography to hide stolen data inside other files stored on Github. |
| T1041 Exfiltration Over C2 Channel |
GroupLeviathan | Leviathan has exfiltrated data over its C2 channel. |
| T1059.001 PowerShell |
GroupLeviathan | Leviathan has used PowerShell for execution. |
| T1074.001 Local Data Staging |
GroupLeviathan | Leviathan has used C:\Windows\Debug and C:\Perflogs as staging directories. |
| T1074.002 Remote Data Staging |
GroupLeviathan | Leviathan has staged data remotely prior to exfiltration. |
| T1078 Valid Accounts |
GroupLeviathan | Leviathan has obtained valid accounts to gain initial access. |
| T1090.003 Multi-hop Proxy |
GroupLeviathan | Leviathan has used multi-hop proxies to disguise the source of their malicious traffic. |
| T1133 External Remote Services |
GroupLeviathan | Leviathan has used external remote services such as virtual private networks (VPN) to gain initial access. |
| T1189 Drive-by Compromise |
GroupLeviathan | Leviathan has infected victims using watering holes. |
| T1203 Exploitation for Client Execution |
GroupLeviathan | Leviathan has exploited multiple Microsoft Office and .NET vulnerabilities for execution, including CVE-2017-0199, CVE-2017-8759, and CVE-2017-11882. |
| T1204.001 Malicious Link |
GroupLeviathan | Leviathan has sent spearphishing email links attempting to get a user to click. |
| T1204.002 Malicious File |
GroupLeviathan | Leviathan has sent spearphishing attachments attempting to get a user to click. |
| T1505.003 Web Shell |
GroupLeviathan | Leviathan relies on web shells for an initial foothold as well as persistence into the victim's systems. |
| T1534 Internal Spearphishing |
GroupLeviathan | Leviathan has conducted internal spearphishing within the victim's environment for lateral movement. |
| T1560 Archive Collected Data |
GroupLeviathan | Leviathan has archived victim's data prior to exfiltration. |
| T1566.001 Spearphishing Attachment |
GroupLeviathan | Leviathan has sent spearphishing emails with malicious attachments, including .rtf, .doc, and .xls files. |
| T1566.002 Spearphishing Link |
GroupLeviathan | Leviathan has sent spearphishing emails with links, often using a fraudulent lookalike domain and stolen branding. |
| T1572 Protocol Tunneling |
GroupLeviathan | Leviathan has used protocol tunneling to further conceal C2 communications and infrastructure. |
| T1583.001 Domains |
GroupLeviathan | Leviathan has established domains that impersonate legitimate entities to use for targeting efforts. |
| T1585.001 Social Media Accounts |
GroupLeviathan | Leviathan has created new social media accounts for targeting efforts. |
| T1585.002 Email Accounts |
GroupLeviathan | Leviathan has created new email accounts for targeting efforts. |
| T1586.001 Social Media Accounts |
GroupLeviathan | Leviathan has compromised social media accounts to conduct social engineering attacks. |
| T1586.002 Email Accounts |
GroupLeviathan | Leviathan has compromised email accounts to conduct social engineering attacks. |
| T1589.001 Credentials |
GroupLeviathan | Leviathan has collected compromised credentials to use for targeting efforts. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.