ATT&CKReferencesNCC Group Chimera January 2021

NCC Group Chimera January 2021

Jansen, W . (2021, January 12). Abusing cloud services to fly under the radar. Retrieved September 12, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples51

TechniqueUsed byProcedure example
T1003.003
NTDS
GroupChimera

Chimera has gathered the SYSTEM registry and ntds.dit files from target systems. Chimera specifically has used the NtdsAudit tool to dump the password hashes of domain users via msadcs.exe "NTDS.dit" -s "SYSTEM" -p RecordedTV_pdmp.txt --users-csv RecordedTV_users.csv and used ntdsutil to copy the Active Directory database.

T1007
System Service Discovery
GroupChimera

Chimera has used net start and net use for system service discovery.

T1012
Query Registry
GroupChimera

Chimera has queried Registry keys using reg query \\<host>\HKU\<SID>\SOFTWARE\Microsoft\Terminal Server Client\Servers and reg query \\<host>\HKU\<SID>\Software\Microsoft\Windows\CurrentVersion\Internet Settings.

T1016
System Network Configuration Discovery
GroupChimera

Chimera has used ipconfig, Ping, and tracert to enumerate the IP address and network environment and settings of the local host.

T1018
Remote System Discovery
GroupChimera

Chimera has utilized various scans and queries to find domain controllers and remote services in the target environment.

T1021.002
SMB/Windows Admin Shares
GroupChimera

Chimera has used Windows admin shares to move laterally.

T1021.006
Windows Remote Management
GroupChimera

Chimera has used WinRM for lateral movement.

T1033
System Owner/User Discovery
GroupChimera

Chimera has used the quser command to show currently logged on users.

T1039
Data from Network Shared Drive
GroupChimera

Chimera has collected data of interest from network shares.

T1041
Exfiltration Over C2 Channel
GroupChimera

Chimera has used Cobalt Strike C2 beacons for data exfiltration.

T1046
Network Service Discovery
GroupChimera

Chimera has used the get -b <start ip> -e <end ip> -p command for network scanning as well as a custom Python tool packed into a Windows executable named Get.exe to scan IP ranges for HTTP.

T1047
Windows Management Instrumentation
GroupChimera

Chimera has used WMIC to execute remote commands.

T1049
System Network Connections Discovery
GroupChimera

Chimera has used netstat -ano | findstr EST to discover network connections.

T1053.005
Scheduled Task
GroupChimera

Chimera has used scheduled tasks to invoke Cobalt Strike including through batch script schtasks /create /ru "SYSTEM" /tn "update" /tr "cmd /c c:\windows\temp\update.bat" /sc once /f /st and to maintain persistence.

T1057
Process Discovery
GroupChimera

Chimera has used tasklist to enumerate processes.

T1059.001
PowerShell
GroupChimera

Chimera has used PowerShell scripts to execute malicious payloads and the DSInternals PowerShell module to make use of Active Directory features.

T1059.003
Windows Command Shell
GroupChimera

Chimera has used the Windows Command Shell and batch scripts for execution on compromised hosts.

T1069.001
Local Groups
GroupChimera

Chimera has used net localgroup administrators to identify accounts with local administrative rights.

T1070.006
Timestomp
GroupChimera

Chimera has used a Windows version of the Linux touch command to modify the date and time stamp on DLLs.

T1071.001
Web Protocols
GroupChimera

Chimera has used HTTPS for C2 communications.

T1071.004
DNS
GroupChimera

Chimera has used Cobalt Strike to encapsulate C2 in DNS traffic.

T1074.001
Local Data Staging
GroupChimera

Chimera has staged stolen data locally on compromised hosts.

T1074.002
Remote Data Staging
GroupChimera

Chimera has staged stolen data on designated servers in the target environment.

T1078.002
Domain Accounts
GroupChimera

Chimera has used compromised domain accounts to gain access to the target environment.

T1083
File and Directory Discovery
GroupChimera

Chimera has utilized multiple commands to identify data of interest in file and directory listings.

T1087.001
Local Account
GroupChimera

Chimera has used net user for account discovery.

T1087.002
Domain Account
GroupChimera

Chimera has has used net user /dom and net user Administrator to enumerate domain accounts including administrator accounts.

T1110.003
Password Spraying
GroupChimera

Chimera has used multiple password spraying attacks against victim's remote services to obtain valid user and administrator accounts.

T1110.004
Credential Stuffing
GroupChimera

Chimera has used credential stuffing against victim's remote services to obtain valid accounts.

T1111
Multi-Factor Authentication Interception
GroupChimera

Chimera has registered alternate phone numbers for compromised users to intercept 2FA codes sent via SMS.

T1114.001
Local Email Collection
GroupChimera

Chimera has harvested data from victim's e-mail including through execution of wmic /node:<ip> process call create "cmd /c copy c:\Users\<username>\<path>\backup.pst c:\windows\temp\backup.pst" copy "i:\<path>\<username>\My Documents\<filename>.pst"
copy
.

T1114.002
Remote Email Collection
GroupChimera

Chimera has harvested data from remote mailboxes including through execution of \\<hostname>\c$\Users\<username>\AppData\Local\Microsoft\Outlook*.ost.

T1119
Automated Collection
GroupChimera

Chimera has used custom DLLs for continuous retrieval of data from memory.

T1124
System Time Discovery
GroupChimera

Chimera has used time /t and net time \\ip/hostname for system time discovery.

T1133
External Remote Services
GroupChimera

Chimera has used legitimate credentials to login to an external VPN, Citrix, SSH, and other remote services.

T1135
Network Share Discovery
GroupChimera

Chimera has used net share and net view to identify network shares of interest.

T1201
Password Policy Discovery
GroupChimera

Chimera has used the NtdsAudit utility to collect information related to accounts and passwords.

T1213.002
Sharepoint
GroupChimera

Chimera has collected documents from the victim's SharePoint.

T1217
Browser Information Discovery
GroupChimera

Chimera has used type \\<hostname>\c$\Users\<username>\Favorites\Links\Bookmarks bar\Imported From IE\*citrix* for bookmark discovery.

T1482
Domain Trust Discovery
GroupChimera

Chimera has nltest /domain_trusts to identify domain trust relationships.

T1550.002
Pass the Hash
GroupChimera

Chimera has dumped password hashes for use in pass the hash authentication attacks.

T1560.001
Archive via Utility
GroupChimera

Chimera has used gzip for Linux OS and a modified RAR software to archive data on Windows hosts.

T1567.002
Exfiltration to Cloud Storage
GroupChimera

Chimera has exfiltrated stolen data to OneDrive accounts.

T1569.002
Service Execution
GroupChimera

Chimera has used PsExec to deploy beacons on compromised systems.

T1570
Lateral Tool Transfer
GroupChimera

Chimera has copied tools between compromised hosts using SMB.

T1572
Protocol Tunneling
GroupChimera

Chimera has encapsulated Cobalt Strike's C2 protocol in DNS and HTTPS.

T1574.001
DLL
GroupChimera

Chimera has used side loading to place malicious DLLs in memory.

T1588.002
Tool
GroupChimera

Chimera has obtained and used tools such as BloodHound, Cobalt Strike, Mimikatz, and PsExec.

T1589.001
Credentials
GroupChimera

Chimera has collected credentials for the target organization from previous breaches for use in brute force attacks.

T1680
Local Storage Discovery
GroupChimera

Chimera has used `fsutil fsinfo drives`, `systeminfo`, and `vssadmin list shadows` for system information including shadow volumes and drive information.

Showing the first 50.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.