ATT&CKReferencesTrend Micro Tick November 2019

Trend Micro Tick November 2019

Chen, J. et al. (2019, November). Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data. Retrieved June 9, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software5

Campaigns0

None recorded.

Procedure examples60

TechniqueUsed byProcedure example
T1007
System Service Discovery
GroupBRONZE BUTLER

BRONZE BUTLER has used TROJ_GETVERSION to discover system services.

T1016
System Network Configuration Discovery
Malwaredown_new

down_new has the ability to identify the MAC address of a compromised host.

T1016
System Network Configuration Discovery
MalwareAvenger

Avenger can identify the domain of the compromised host.

T1027.001
Binary Padding
GroupBRONZE BUTLER

BRONZE BUTLER downloader code has included "0" characters at the end of the file to inflate the file size in a likely attempt to evade anti-virus detection.

T1027.003
Steganography
MalwareBBK

BBK can extract a malicious Portable Executable (PE) from a photo.

T1027.003
Steganography
GroupBRONZE BUTLER

BRONZE BUTLER has used steganography in multiple operations to conceal malicious payloads.

T1027.003
Steganography
MalwareABK

ABK can extract a malicious Portable Executable (PE) from a photo.

T1027.003
Steganography
MalwareAvenger

Avenger can extract backdoor malware from downloaded images.

T1027.003
Steganography
Malwarebuild_downer

build_downer can extract malware from a downloaded JPEG.

T1027.013
Encrypted/Encoded File
MalwareAvenger

Avenger has the ability to XOR encrypt files to be sent to C2.

T1036
Masquerading
GroupBRONZE BUTLER

BRONZE BUTLER has masked executables with document file icons including Word and Adobe PDF.

T1036.002
Right-to-Left Override
GroupBRONZE BUTLER

BRONZE BUTLER has used Right-to-Left Override to deceive victims into executing several strains of malware.

T1036.004
Masquerade Task or Service
Malwarebuild_downer

build_downer has added itself to the Registry Run key as "NVIDIA" to appear legitimate.

T1055
Process Injection
MalwareABK

ABK has the ability to inject shellcode into svchost.exe.

T1055
Process Injection
MalwareBBK

BBK has the ability to inject shellcode into svchost.exe.

T1055
Process Injection
MalwareAvenger

Avenger has the ability to inject shellcode into svchost.exe.

T1057
Process Discovery
Malwaredown_new

down_new has the ability to list running processes on a compromised host.

T1057
Process Discovery
MalwareAvenger

Avenger has the ability to use Tasklist to identify running processes.

T1059.003
Windows Command Shell
MalwareBBK

BBK has the ability to use cmd to run a Portable Executable (PE) on the compromised host.

T1059.003
Windows Command Shell
MalwareABK

ABK has the ability to use cmd to run a Portable Executable (PE) on the compromised host.

T1059.005
Visual Basic
GroupBRONZE BUTLER

BRONZE BUTLER has used VBS and VBE scripts for execution.

T1059.006
Python
GroupBRONZE BUTLER

BRONZE BUTLER has made use of Python-based remote access tools.

T1071.001
Web Protocols
MalwareABK

ABK has the ability to use HTTP in communications with C2.

T1071.001
Web Protocols
MalwareBBK

BBK has the ability to use HTTP in communications with C2.

T1071.001
Web Protocols
MalwareAvenger

Avenger has the ability to use HTTP in communication with C2.

T1071.001
Web Protocols
Malwaredown_new

down_new has the ability to use HTTP in C2 communications.

T1082
System Information Discovery
MalwareAvenger

Avenger has the ability to identify the OS architecture on a compromised host.

T1083
File and Directory Discovery
MalwareAvenger

Avenger has the ability to browse files in directories such as Program Files and the Desktop.

T1083
File and Directory Discovery
Malwaredown_new

down_new has the ability to list the directories on a compromised host.

T1105
Ingress Tool Transfer
Malwarebuild_downer

build_downer has the ability to download files from C2 to the infected host.

T1105
Ingress Tool Transfer
MalwareBBK

BBK has the ability to download files from C2 to the infected host.

T1105
Ingress Tool Transfer
Malwaredown_new

down_new has the ability to download files to the compromised host.

T1105
Ingress Tool Transfer
MalwareAvenger

Avenger has the ability to download files from C2 to a compromised host.

T1105
Ingress Tool Transfer
MalwareABK

ABK has the ability to download files from C2.

T1106
Native API
MalwareBBK

BBK has the ability to use the CreatePipe API to add a sub-process for execution via cmd.

T1106
Native API
Malwarebuild_downer

build_downer has the ability to use the WinExec API to execute malware on a compromised host.

T1113
Screen Capture
GroupBRONZE BUTLER

BRONZE BUTLER has used a tool to capture screenshots.

T1124
System Time Discovery
Malwarebuild_downer

build_downer has the ability to determine the local time to ensure malware installation only happens during the hours that the infected system is active.

T1132.001
Standard Encoding
Malwaredown_new

down_new has the ability to base64 encode C2 communications.

T1140
Deobfuscate/Decode Files or Information
MalwareBBK

BBK has the ability to decrypt AES encrypted payloads.

T1140
Deobfuscate/Decode Files or Information
MalwareAvenger

Avenger has the ability to decrypt files downloaded from C2.

T1140
Deobfuscate/Decode Files or Information
MalwareABK

ABK has the ability to decrypt AES encrypted payloads.

T1203
Exploitation for Client Execution
GroupBRONZE BUTLER

BRONZE BUTLER has exploited Microsoft Office vulnerabilities CVE-2014-4114, CVE-2018-0802, and CVE-2018-0798 for execution.

T1204.002
Malicious File
GroupBRONZE BUTLER

BRONZE BUTLER has attempted to get users to launch malicious Microsoft Word attachments delivered via spearphishing emails.

T1518
Software Discovery
GroupBRONZE BUTLER

BRONZE BUTLER has used tools to enumerate software installed on an infected host.

T1518
Software Discovery
Malwaredown_new

down_new has the ability to gather information on installed applications.

T1518.001
Security Software Discovery
Malwaredown_new

down_new has the ability to detect anti-virus products and processes on a compromised host.

T1518.001
Security Software Discovery
MalwareAvenger

Avenger has the ability to identify installed anti-virus products on a compromised host.

T1518.001
Security Software Discovery
MalwareABK

ABK has the ability to identify the installed anti-virus product on the compromised host.

T1518.001
Security Software Discovery
Malwarebuild_downer

build_downer has the ability to detect if the infected host is running an anti-virus process.

Showing the first 50.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.