ATT&CKReferencesCitizen Lab Stealth Falcon May 2016

Citizen Lab Stealth Falcon May 2016

Marczak, B. and Scott-Railton, J.. (2016, May 29). Keep Calm and (Don’t) Enable Macros: A New Threat Actor Targets UAE Dissidents. Retrieved June 8, 2016.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples16

TechniqueUsed byProcedure example
T1005
Data from Local System
GroupStealth Falcon

Stealth Falcon malware gathers data from the local victim system.

T1012
Query Registry
GroupStealth Falcon

Stealth Falcon malware attempts to determine the installed version of .NET by querying the Registry.

T1016
System Network Configuration Discovery
GroupStealth Falcon

Stealth Falcon malware gathers the Address Resolution Protocol (ARP) table from the victim.

T1033
System Owner/User Discovery
GroupStealth Falcon

Stealth Falcon malware gathers the registered user and primary owner name via WMI.

T1041
Exfiltration Over C2 Channel
GroupStealth Falcon

After data is collected by Stealth Falcon malware, it is exfiltrated over the existing C2 channel.

T1047
Windows Management Instrumentation
GroupStealth Falcon

Stealth Falcon malware gathers system information via Windows Management Instrumentation (WMI).

T1053.005
Scheduled Task
GroupStealth Falcon

Stealth Falcon malware creates a scheduled task entitled “IE Web Cache” to execute a malicious file hourly.

T1057
Process Discovery
GroupStealth Falcon

Stealth Falcon malware gathers a list of running processes.

T1059
Command and Scripting Interpreter
GroupStealth Falcon

Stealth Falcon malware uses WMI to script data collection and command execution on the victim.

T1059.001
PowerShell
GroupStealth Falcon

Stealth Falcon malware uses PowerShell commands to perform various functions, including gathering system information via WMI and executing commands from its C2 server.

T1071.001
Web Protocols
GroupStealth Falcon

Stealth Falcon malware communicates with its C2 server via HTTPS.

T1082
System Information Discovery
GroupStealth Falcon

Stealth Falcon malware gathers system information via WMI, including the system directory, build number, serial number, version, manufacturer, model, and total physical memory.

T1555
Credentials from Password Stores
GroupStealth Falcon

Stealth Falcon malware gathers passwords from multiple sources, including Windows Credential Vault and Outlook.

T1555.003
Credentials from Web Browsers
GroupStealth Falcon

Stealth Falcon malware gathers passwords from multiple sources, including Internet Explorer, Firefox, and Chrome.

T1555.004
Windows Credential Manager
GroupStealth Falcon

Stealth Falcon malware gathers passwords from the Windows Credential Vault.

T1573.001
Symmetric Cryptography
GroupStealth Falcon

Stealth Falcon malware encrypts C2 traffic using RC4 with a hard-coded key.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.