FireEye. (2018, March 16). Suspected Chinese Cyber Espionage Group (TEMP.Periscope) Targeting U.S. Engineering and Maritime Industries. Retrieved April 11, 2018.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003 OS Credential Dumping |
MalwareHOMEFRY | HOMEFRY can perform credential dumping. |
| T1005 Data from Local System |
MalwareChina Chopper | China Chopper's server component can upload local files. |
| T1012 Query Registry |
MalwareDerusbi | Derusbi is capable of enumerating Registry keys and values. |
| T1018 Remote System Discovery |
MalwareMURKYTOP | MURKYTOP has the capability to identify remote hosts on connected networks. |
| T1027.013 Encrypted/Encoded File |
MalwareHOMEFRY | Some strings in HOMEFRY are obfuscated with XOR x56. |
| T1046 Network Service Discovery |
MalwareMURKYTOP | MURKYTOP has the capability to scan for open ports on hosts in a connected network. |
| T1046 Network Service Discovery |
MalwareChina Chopper | China Chopper's server component can spider authentication portals. |
| T1053.002 At |
MalwareMURKYTOP | MURKYTOP has the capability to schedule remote AT jobs. |
| T1056.001 Keylogging |
MalwareDerusbi | Derusbi is capable of logging keystrokes. |
| T1057 Process Discovery |
MalwareDerusbi | Derusbi collects current and parent process IDs. |
| T1059.001 PowerShell |
GroupLeviathan | Leviathan has used PowerShell for execution. |
| T1059.003 Windows Command Shell |
MalwareMURKYTOP | MURKYTOP uses the command-line interface. |
| T1059.003 Windows Command Shell |
MalwareHOMEFRY | HOMEFRY uses a command-line interface. |
| T1059.004 Unix Shell |
MalwareDerusbi | Derusbi is capable of creating a remote Bash shell and executing commands. |
| T1069 Permission Groups Discovery |
MalwareMURKYTOP | MURKYTOP has the capability to retrieve information about groups. |
| T1070.004 File Deletion |
MalwareMURKYTOP | MURKYTOP has the capability to delete local files. |
| T1070.004 File Deletion |
MalwareDerusbi | Derusbi is capable of deleting files. It has been observed loading a Linux Kernel Module (LKM) and then deleting it from the hard disk as well as overwriting the data with null bytes. |
| T1070.006 Timestomp |
MalwareChina Chopper | China Chopper's server component can change the timestamp of files. |
| T1071.001 Web Protocols |
MalwareChina Chopper | China Chopper's server component executes code sent via HTTP POST commands. |
| T1074.001 Local Data Staging |
GroupLeviathan | Leviathan has used C:\Windows\Debug and C:\Perflogs as staging directories. |
| T1082 System Information Discovery |
MalwareMURKYTOP | MURKYTOP has the capability to retrieve information about the OS. |
| T1083 File and Directory Discovery |
MalwareDerusbi | Derusbi is capable of obtaining directory, file, and drive listings. |
| T1083 File and Directory Discovery |
MalwareChina Chopper | China Chopper's server component can list directory contents. |
| T1087.001 Local Account |
MalwareMURKYTOP | MURKYTOP has the capability to retrieve information about users on remote hosts. |
| T1102.001 Dead Drop Resolver |
MalwareBLACKCOFFEE | BLACKCOFFEE uses Microsoft’s TechNet Web portal to obtain a dead drop resolver containing an encoded tag with the IP address of a command and control server. |
| T1102.002 Bidirectional Communication |
MalwareBLACKCOFFEE | BLACKCOFFEE has also obfuscated its C2 traffic as normal traffic to sites such as Github. |
| T1102.003 One-Way Communication |
GroupLeviathan | Leviathan has received C2 instructions from user profiles created on legitimate websites such as Github and TechNet. |
| T1105 Ingress Tool Transfer |
MalwareChina Chopper | China Chopper's server component can download remote files. |
| T1105 Ingress Tool Transfer |
GroupLeviathan | Leviathan has downloaded additional scripts and files from adversary-controlled servers. |
| T1110.001 Password Guessing |
MalwareChina Chopper | China Chopper's server component can perform brute force password guessing against authentication portals. |
| T1113 Screen Capture |
MalwareDerusbi | Derusbi is capable of performing screen captures. |
| T1123 Audio Capture |
MalwareDerusbi | Derusbi is capable of performing audio captures. |
| T1125 Video Capture |
MalwareDerusbi | Derusbi is capable of capturing video. |
| T1135 Network Share Discovery |
MalwareMURKYTOP | MURKYTOP has the capability to retrieve information about shares on remote hosts. |
| T1197 BITS Jobs |
GroupLeviathan | |
| T1203 Exploitation for Client Execution |
GroupLeviathan | Leviathan has exploited multiple Microsoft Office and .NET vulnerabilities for execution, including CVE-2017-0199, CVE-2017-8759, and CVE-2017-11882. |
| T1546.003 Windows Management Instrumentation Event Subscription |
GroupLeviathan | Leviathan has used WMI for persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupLeviathan | Leviathan has used JavaScript to create a shortcut file in the Startup folder that points to its main backdoor. |
| T1547.009 Shortcut Modification |
GroupLeviathan | Leviathan has used JavaScript to create a shortcut file in the Startup folder that points to its main backdoor. |
| T1553.002 Code Signing |
GroupLeviathan | Leviathan has used stolen code signing certificates to sign malware. |
| T1567.002 Exfiltration to Cloud Storage |
GroupLeviathan | Leviathan has used an uploader known as LUNCHMONEY that can exfiltrate files to Dropbox. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.