ATT&CKReferencesESET BackdoorDiplomacy Jun 2021

ESET BackdoorDiplomacy Jun 2021

Adam Burgher. (2021, June 10). BackdoorDiplomacy: Upgrading from Quarian to Turian. Retrieved September 1, 2021

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples33

TechniqueUsed byProcedure example
T1001.001
Junk Data
MalwareTurian

Turian can insert pseudo-random characters into its network encryption setup.

T1016
System Network Configuration Discovery
MalwareTurian

Turian can retrieve the internal IP address of a compromised host.

T1027
Obfuscated Files or Information
MalwareTurian

Turian can use VMProtect for obfuscation.

T1027
Obfuscated Files or Information
GroupBackdoorDiplomacy

BackdoorDiplomacy has obfuscated tools and malware it uses with VMProtect.

T1033
System Owner/User Discovery
MalwareTurian

Turian can retrieve usernames.

T1036.004
Masquerade Task or Service
GroupBackdoorDiplomacy

BackdoorDiplomacy has disguised their backdoor droppers with naming conventions designed to blend into normal operations.

T1036.004
Masquerade Task or Service
MalwareTurian

Turian can disguise as a legitimate service to blend into normal operations.

T1036.005
Match Legitimate Resource Name or Location
GroupBackdoorDiplomacy

BackdoorDiplomacy has dropped implants in folders named for legitimate software.

T1046
Network Service Discovery
GroupBackdoorDiplomacy

BackdoorDiplomacy has used SMBTouch, a vulnerability scanner, to determine whether a target is vulnerable to EternalBlue malware.

T1049
System Network Connections Discovery
GroupBackdoorDiplomacy

BackdoorDiplomacy has used NetCat and PortQry to enumerate network connections and display the status of related TCP and UDP ports.

T1055.001
Dynamic-link Library Injection
GroupBackdoorDiplomacy

BackdoorDiplomacy has dropped legitimate software onto a compromised host and used it to execute malicious DLLs.

T1059.003
Windows Command Shell
MalwareTurian

Turian can create a remote shell and execute commands using cmd.

T1059.004
Unix Shell
MalwareTurian

Turian has the ability to use /bin/sh to execute commands.

T1059.006
Python
MalwareTurian

Turian has the ability to use Python to spawn a Unix shell.

T1071.001
Web Protocols
MalwareTurian

Turian has the ability to use HTTP for its C2.

T1074.001
Local Data Staging
MalwareTurian

Turian can store copied files in a specific directory prior to exfiltration.

T1074.001
Local Data Staging
GroupBackdoorDiplomacy

BackdoorDiplomacy has copied files of interest to the main drive's recycle bin.

T1082
System Information Discovery
MalwareTurian

Turian can retrieve system information including OS version, memory usage, local hostname, and system adapter information.

T1083
File and Directory Discovery
MalwareTurian

Turian can search for specific files and list directories.

T1095
Non-Application Layer Protocol
GroupBackdoorDiplomacy

BackdoorDiplomacy has used EarthWorm for network tunneling with a SOCKS5 server and port transfer functionalities.

T1105
Ingress Tool Transfer
GroupBackdoorDiplomacy

BackdoorDiplomacy has downloaded additional files and tools onto a compromised host.

T1105
Ingress Tool Transfer
MalwareTurian

Turian can download additional files and tools from its C2.

T1113
Screen Capture
MalwareTurian

Turian has the ability to take screenshots.

T1120
Peripheral Device Discovery
MalwareTurian

Turian can scan for removable media to collect data.

T1120
Peripheral Device Discovery
GroupBackdoorDiplomacy

BackdoorDiplomacy has used an executable to detect removable media, such as USB flash drives.

T1140
Deobfuscate/Decode Files or Information
MalwareTurian

Turian has the ability to use a XOR decryption key to extract C2 server domains and IP addresses.

T1190
Exploit Public-Facing Application
GroupBackdoorDiplomacy

BackdoorDiplomacy has exploited CVE-2020-5902, an F5 BIP-IP vulnerability, to drop a Linux backdoor. BackdoorDiplomacy has also exploited mis-configured Plesk servers.

T1505.003
Web Shell
GroupBackdoorDiplomacy

BackdoorDiplomacy has used web shells to establish an initial foothold and for lateral movement within a victim's system.

T1547.001
Registry Run Keys / Startup Folder
MalwareTurian

Turian can establish persistence by adding Registry Run keys.

T1560.001
Archive via Utility
MalwareTurian

Turian can use WinRAR to create a password-protected archive for files of interest.

T1574.001
DLL
GroupBackdoorDiplomacy

BackdoorDiplomacy has executed DLL search order hijacking.

T1588.001
Malware
GroupBackdoorDiplomacy

BackdoorDiplomacy has obtained and used leaked malware, including DoublePulsar, EternalBlue, EternalRocks, and EternalSynergy, in its operations.

T1588.002
Tool
GroupBackdoorDiplomacy

BackdoorDiplomacy has obtained a variety of open-source reconnaissance and red team tools for discovery and lateral movement.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.