ATT&CKReferencesLotus Blossom Jun 2015

Lotus Blossom Jun 2015

Falcone, R., et al.. (2015, June 16). Operation Lotus Blossom. Retrieved February 15, 2016.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples15

TechniqueUsed byProcedure example
T1007
System Service Discovery
MalwareElise

Elise executes net start after initial communication is made to the remote server.

T1016
System Network Configuration Discovery
MalwareElise

Elise executes ipconfig /all after initial communication is made to the remote server.

T1027.013
Encrypted/Encoded File
MalwareElise

Elise encrypts several of its files, including configuration files.

T1036.005
Match Legitimate Resource Name or Location
MalwareElise

If installing itself as a service fails, Elise instead writes itself as a file named svchost.exe saved in %APPDATA%\Microsoft\Network.

T1055.001
Dynamic-link Library Injection
MalwareElise

Elise injects DLL files into iexplore.exe.

T1070.006
Timestomp
MalwareElise

Elise performs timestomping of a CAB file it creates.

T1071.001
Web Protocols
MalwareElise

Elise communicates over HTTP or HTTPS for C2.

T1082
System Information Discovery
MalwareElise

Elise executes systeminfo after initial communication is made to the remote server.

T1083
File and Directory Discovery
MalwareElise

A variant of Elise executes dir C:\progra~1 when initially run.

T1087.001
Local Account
MalwareElise

Elise executes net user after initial communication is made to the remote server.

T1132.001
Standard Encoding
MalwareElise

Elise exfiltrates data using cookie values that are Base64-encoded.

T1218.011
Rundll32
MalwareElise

After copying itself to a DLL file, a variant of Elise calls the DLL file using rundll32.exe.

T1543.003
Windows Service
MalwareElise

Elise configures itself as a service.

T1547.001
Registry Run Keys / Startup Folder
MalwareElise

If establishing persistence by installation as a new service fails, one variant of Elise establishes persistence for the created .exe file by setting the following Registry key: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\svchost : %APPDATA%\Microsoft\Network\svchost.exe. Other variants have set the following Registry keys for persistence: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\imejp : [self] and HKCU\Software\Microsoft\Windows\CurrentVersion\Run\IAStorD.

T1573.001
Symmetric Cryptography
MalwareElise

Elise encrypts exfiltrated data with RC4.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.