ATT&CKReferencesCycraft Chimera April 2020

Cycraft Chimera April 2020

Cycraft. (2020, April 15). APT Group Chimera - APT Operation Skeleton key Targets Taiwan Semiconductor Vendors. Retrieved August 24, 2020..

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples17

TechniqueUsed byProcedure example
T1003.003
NTDS
GroupChimera

Chimera has gathered the SYSTEM registry and ntds.dit files from target systems. Chimera specifically has used the NtdsAudit tool to dump the password hashes of domain users via msadcs.exe "NTDS.dit" -s "SYSTEM" -p RecordedTV_pdmp.txt --users-csv RecordedTV_users.csv and used ntdsutil to copy the Active Directory database.

T1021.001
Remote Desktop Protocol
GroupChimera

Chimera has used RDP to access targeted systems.

T1021.002
SMB/Windows Admin Shares
GroupChimera

Chimera has used Windows admin shares to move laterally.

T1027.010
Command Obfuscation
GroupChimera

Chimera has encoded PowerShell commands.

T1036.005
Match Legitimate Resource Name or Location
GroupChimera

Chimera has renamed malware to GoogleUpdate.exe and WinRAR to jucheck.exe, RecordedTV.ms, teredo.tmp, update.exe, and msadcs1.exe.

T1047
Windows Management Instrumentation
GroupChimera

Chimera has used WMIC to execute remote commands.

T1053.005
Scheduled Task
GroupChimera

Chimera has used scheduled tasks to invoke Cobalt Strike including through batch script schtasks /create /ru "SYSTEM" /tn "update" /tr "cmd /c c:\windows\temp\update.bat" /sc once /f /st and to maintain persistence.

T1059.001
PowerShell
GroupChimera

Chimera has used PowerShell scripts to execute malicious payloads and the DSInternals PowerShell module to make use of Active Directory features.

T1070.004
File Deletion
GroupChimera

Chimera has performed file deletion to evade detection.

T1078
Valid Accounts
GroupChimera

Chimera has used a valid account to maintain persistence via scheduled task.

T1087.002
Domain Account
GroupChimera

Chimera has has used net user /dom and net user Administrator to enumerate domain accounts including administrator accounts.

T1105
Ingress Tool Transfer
GroupChimera

Chimera has remotely copied tools and malware onto targeted systems.

T1106
Native API
GroupChimera

Chimera has used direct Windows system calls by leveraging Dumpert.

T1133
External Remote Services
GroupChimera

Chimera has used legitimate credentials to login to an external VPN, Citrix, SSH, and other remote services.

T1556.001
Domain Controller Authentication
GroupChimera

Chimera's malware has altered the NTLM authentication program on domain controllers to allow Chimera to login without a valid credential.

T1560.001
Archive via Utility
GroupChimera

Chimera has used gzip for Linux OS and a modified RAR software to archive data on Windows hosts.

T1588.002
Tool
GroupChimera

Chimera has obtained and used tools such as BloodHound, Cobalt Strike, Mimikatz, and PsExec.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.