ATT&CKReferencesSentinelOne Agrius 2021

SentinelOne Agrius 2021

Amitai Ben & Shushan Ehrlich. (2021, May). From Wiper to Ransomware: The Evolution of Agrius. Retrieved May 21, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software3

Campaigns0

None recorded.

Procedure examples42

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareIPsec Helper

IPsec Helper can identify specific files and folders for follow-on exfiltration.

T1021.001
Remote Desktop Protocol
GroupAgrius

Agrius tunnels RDP traffic through deployed web shells to access victim environments via compromised accounts. Agrius used the Plink tool to tunnel RDP connections for remote access and lateral movement in victim environments.

T1027.009
Embedded Payloads
MalwareDEADWOOD

DEADWOOD contains an embedded, AES-encrypted payload labeled METADATA that provides configuration information for follow-on execution.

T1027.013
Encrypted/Encoded File
MalwareDEADWOOD

DEADWOOD contains an embedded, AES-encrypted resource named METADATA that contains configuration information for follow-on execution.

T1027.013
Encrypted/Encoded File
MalwareIPsec Helper

IPsec Helper contains an embedded XML configuration file with an encrypted list of command and control servers. These are written to an external configuration file during execution.

T1036.004
Masquerade Task or Service
MalwareDEADWOOD

DEADWOOD will attempt to masquerade its service execution using benign-looking names such as ScDeviceEnums.

T1041
Exfiltration Over C2 Channel
MalwareIPsec Helper

IPsec Helper exfiltrates specific files through its command and control framework.

T1053.005
Scheduled Task
MalwareApostle

Apostle achieves persistence by creating a scheduled task, such as MicrosoftCrashHandlerUAC.

T1057
Process Discovery
MalwareIPsec Helper

IPsec Helper can identify the process it is currently running under and its number, and pass this back to a command and control node.

T1057
Process Discovery
MalwareApostle

Apostle retrieves a list of all running processes on a victim host, and stops all services containing the string "sql," likely to propagate ransomware activity to database files.

T1059.001
PowerShell
MalwareIPsec Helper

IPsec Helper can run arbitrary PowerShell commands passed to it.

T1059.003
Windows Command Shell
GroupAgrius

Agrius uses ASPXSpy web shells to enable follow-on command execution via cmd.exe.

T1059.003
Windows Command Shell
MalwareIPsec Helper

IPsec Helper can run arbitrary commands passed to it through cmd.exe.

T1059.005
Visual Basic
MalwareIPsec Helper

IPsec Helper can run arbitrary Visual Basic scripts and commands passed to it.

T1070
Indicator Removal
MalwareIPsec Helper

IPsec Helper can delete various registry keys related to its execution and use.

T1070.004
File Deletion
MalwareApostle

Apostle writes batch scripts to disk, such as system.bat and remover.bat, that perform various anti-analysis and anti-forensic tasks, before finally deleting themselves at the end of execution. Apostle attempts to delete itself after encryption or wiping operations are complete and before shutting down the victim machine.

T1070.004
File Deletion
MalwareIPsec Helper

IPsec Helper can delete itself when given the appropriate command.

T1070.009
Clear Persistence
MalwareIPsec Helper

IPsec Helper can delete various service traces related to persistent execution when commanded.

T1071.001
Web Protocols
MalwareIPsec Helper

IPsec Helper connects to command and control servers via HTTP POST requests based on parameters hard-coded into the malware.

T1112
Modify Registry
MalwareIPsec Helper

IPsec Helper can make arbitrary changes to registry keys based on provided input.

T1124
System Time Discovery
MalwareDEADWOOD

DEADWOOD will set a timestamp value to determine when wiping functionality starts. When the timestamp is met on the system, a trigger file is created on the operating system allowing for execution to proceed. If the timestamp is in the past, the wiper will execute immediately.

T1140
Deobfuscate/Decode Files or Information
MalwareDEADWOOD

DEADWOOD XORs some strings within the binary using the value 0xD5, and deobfuscates these items at runtime.

T1140
Deobfuscate/Decode Files or Information
MalwareApostle

Apostle compiled code is obfuscated in an unspecified fashion prior to delivery to victims.

T1140
Deobfuscate/Decode Files or Information
GroupAgrius

Agrius has deployed base64-encoded variants of ASPXSpy to evade detection.

T1190
Exploit Public-Facing Application
GroupAgrius

Agrius exploits public-facing applications for initial access to victim environments. Examples include widespread attempts to exploit CVE-2018-13379 in FortiOS devices and SQL injection activity.

T1480
Execution Guardrails
MalwareApostle

Apostle's ransomware variant requires that a base64-encoded argument is passed when executed, that is used as the Public Key for subsequent encryption operations. If Apostle is executed without this argument, it automatically runs a self-delete function.

T1485
Data Destruction
MalwareDEADWOOD

DEADWOOD overwrites files on victim systems with random data to effectively destroy them.

T1485
Data Destruction
MalwareApostle

Apostle initially masqueraded as ransomware but actual functionality is a data destruction tool, supported by an internal name linked to an early version, wiper-action. Apostle writes random data to original files after an encrypted copy is created, along with resizing the original file to zero and changing time property metadata before finally deleting the original file.

T1486
Data Encrypted for Impact
MalwareApostle

Apostle creates new, encrypted versions of files then deletes the originals, with the new filenames consisting of a random GUID and ".lock" for an extension.

T1497.003
Time Based Checks
MalwareIPsec Helper

IPsec Helper will sleep for a random number of seconds, iterating 200 times over sleeps between one to three seconds, before continuing execution flow.

T1505.003
Web Shell
GroupAgrius

Agrius typically deploys a variant of the ASPXSpy web shell following initial access via exploitation.

T1529
System Shutdown/Reboot
MalwareApostle

Apostle reboots the victim machine following wiping and related activity.

T1531
Account Access Removal
MalwareDEADWOOD

DEADWOOD changes the password for local and domain users via net.exe to a random 32 character string to prevent these accounts from logging on. Additionally, DEADWOOD will terminate the winlogon.exe process to prevent attempts to log on to the infected system.

T1543.003
Windows Service
GroupAgrius

Agrius has deployed IPsec Helper malware post-exploitation and registered it as a service for persistence.

T1561.001
Disk Content Wipe
MalwareApostle

Apostle searches for files on available drives based on a list of extensions hard-coded into the sample for follow-on wipe activity.

T1561.001
Disk Content Wipe
MalwareDEADWOOD

DEADWOOD deletes files following overwriting them with random data.

T1561.002
Disk Structure Wipe
MalwareDEADWOOD

DEADWOOD opens and writes zeroes to the first 512 bytes of each drive, deleting the MBR. DEADWOOD then sends the control code IOCTL_DISK_DELETE_DRIVE_LAYOUT to ensure the MBR is removed from the drive.

T1569.002
Service Execution
MalwareDEADWOOD

DEADWOOD can be executed as a service using various names, such as ScDeviceEnums.

T1569.002
Service Execution
MalwareIPsec Helper

IPsec Helper is run as a Windows service in victim environments.

T1570
Lateral Tool Transfer
MalwareIPsec Helper

IPsec Helper can download additional payloads from command and control nodes and execute them.

T1583
Acquire Infrastructure
GroupAgrius

Agrius typically uses commercial VPN services for anonymizing last-hop traffic to victim networks, such as ProtonVPN.

T1685.005
Clear Windows Event Logs
MalwareApostle

Apostle will attempt to delete all event logs on a victim machine following file wipe activity.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.