ATT&CKReferencesSymantec Bilbug 2022

Symantec Bilbug 2022

Symntec Threat Hunter Team. (2022, November 12). Billbug: State-sponsored Actor Targets Cert Authority, Government Agencies in Multiple Asian Countries. Retrieved March 15, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software2

Campaigns0

None recorded.

Procedure examples18

TechniqueUsed byProcedure example
T1018
Remote System Discovery
GroupLotus Blossom

Lotus Blossom has used Ping to identify remote systems.

T1020
Automated Exfiltration
MalwareHannotog

Hannotog can upload encyrpted data for exfiltration.

T1027.013
Encrypted/Encoded File
MalwareSagerunex

Sagerunex can be passed a reference to an XOR-encrypted configuration file at runtime.

T1046
Network Service Discovery
GroupLotus Blossom

Lotus Blossom has used port scanners to enumerate services on remote hosts.

T1057
Process Discovery
MalwareSagerunex

Sagerunex identifies the `explorer.exe` process on the executing system.

T1059.003
Windows Command Shell
MalwareHannotog

Hannotog can execute various `cmd.exe /c %s` commands.

T1071.001
Web Protocols
MalwareSagerunex

Sagerunex communicates via HTTPS, at times using a hard-coded User Agent of `Mozilla/5.0 (compatible; MSIE 7.0; Win32)`.

T1074.001
Local Data Staging
MalwareSagerunex

Sagerunex gathers host information and stages it locally as a RAR file prior to exfiltration. Sagerunex stores logged data in an encrypted file located at `%TEMP%/TS_FB56.tmp` during execution.

T1087.002
Domain Account
GroupLotus Blossom

Lotus Blossom has used `net` commands and tools such as AdFind to profile domain accounts associated with victim machines and make Active Directory queries.

T1105
Ingress Tool Transfer
MalwareHannotog

Hannotog can download additional files to the victim machine.

T1134
Access Token Manipulation
MalwareSagerunex

Sagerunex finds the `explorer.exe` process after execution and uses it to change the token of its executing thread.

T1482
Domain Trust Discovery
GroupLotus Blossom

Lotus Blossom has used tools such as AdFind to make Active Directory queries.

T1489
Service Stop
MalwareHannotog

Hannotog can stop Windows services.

T1543.003
Windows Service
MalwareHannotog

Hannotog creates a new service for persistence.

T1560.001
Archive via Utility
GroupLotus Blossom

Lotus Blossom has used WinRAR for compressing data in RAR format.

T1571
Non-Standard Port
MalwareHannotog

Hannotog uses non-standard listening ports, such as UDP 5900, for command and control purposes.

T1573.002
Asymmetric Cryptography
MalwareSagerunex

Sagerunex uses HTTPS for command and control communication.

T1686
Disable or Modify System Firewall
MalwareHannotog

Hannotog can modify local firewall settings via `netsh` commands to open a listening UDP port.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.