Symntec Threat Hunter Team. (2022, November 12). Billbug: State-sponsored Actor Targets Cert Authority, Government Agencies in Multiple Asian Countries. Retrieved March 15, 2025.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1018 Remote System Discovery |
GroupLotus Blossom | Lotus Blossom has used Ping to identify remote systems. |
| T1020 Automated Exfiltration |
MalwareHannotog | Hannotog can upload encyrpted data for exfiltration. |
| T1027.013 Encrypted/Encoded File |
MalwareSagerunex | Sagerunex can be passed a reference to an XOR-encrypted configuration file at runtime. |
| T1046 Network Service Discovery |
GroupLotus Blossom | Lotus Blossom has used port scanners to enumerate services on remote hosts. |
| T1057 Process Discovery |
MalwareSagerunex | Sagerunex identifies the `explorer.exe` process on the executing system. |
| T1059.003 Windows Command Shell |
MalwareHannotog | Hannotog can execute various `cmd.exe /c %s` commands. |
| T1071.001 Web Protocols |
MalwareSagerunex | Sagerunex communicates via HTTPS, at times using a hard-coded User Agent of `Mozilla/5.0 (compatible; MSIE 7.0; Win32)`. |
| T1074.001 Local Data Staging |
MalwareSagerunex | Sagerunex gathers host information and stages it locally as a RAR file prior to exfiltration. Sagerunex stores logged data in an encrypted file located at `%TEMP%/TS_FB56.tmp` during execution. |
| T1087.002 Domain Account |
GroupLotus Blossom | Lotus Blossom has used `net` commands and tools such as AdFind to profile domain accounts associated with victim machines and make Active Directory queries. |
| T1105 Ingress Tool Transfer |
MalwareHannotog | Hannotog can download additional files to the victim machine. |
| T1134 Access Token Manipulation |
MalwareSagerunex | Sagerunex finds the `explorer.exe` process after execution and uses it to change the token of its executing thread. |
| T1482 Domain Trust Discovery |
GroupLotus Blossom | Lotus Blossom has used tools such as AdFind to make Active Directory queries. |
| T1489 Service Stop |
MalwareHannotog | Hannotog can stop Windows services. |
| T1543.003 Windows Service |
MalwareHannotog | Hannotog creates a new service for persistence. |
| T1560.001 Archive via Utility |
GroupLotus Blossom | Lotus Blossom has used WinRAR for compressing data in RAR format. |
| T1571 Non-Standard Port |
MalwareHannotog | Hannotog uses non-standard listening ports, such as UDP 5900, for command and control purposes. |
| T1573.002 Asymmetric Cryptography |
MalwareSagerunex | Sagerunex uses HTTPS for command and control communication. |
| T1686 Disable or Modify System Firewall |
MalwareHannotog | Hannotog can modify local firewall settings via `netsh` commands to open a listening UDP port. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.