ATT&CKReferencesPalo Alto Sofacy 06-2018

Palo Alto Sofacy 06-2018

Lee, B., Falcone, R. (2018, June 06). Sofacy Group’s Parallel Attacks. Retrieved June 18, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software2

Campaigns0

None recorded.

Procedure examples13

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
GroupAPT28

APT28 encrypted a .dll payload using RTL and a custom encryption algorithm. APT28 has also obfuscated payloads with base64, XOR, and RC4.

T1059.001
PowerShell
GroupAPT28

APT28 downloads and executes PowerShell scripts and performs PowerShell commands.

T1071.001
Web Protocols
MalwareZebrocy

Zebrocy uses HTTP for C2.

T1071.003
Mail Protocols
MalwareZebrocy

Zebrocy uses SMTP and POP3 for C2.

T1082
System Information Discovery
MalwareZebrocy

Zebrocy collects the OS version and computer name. Zebrocy also runs the systeminfo command to gather system information.

T1105
Ingress Tool Transfer
MalwareZebrocy

Zebrocy obtains additional code to execute on the victim's machine, including the downloading of a secondary payload.

T1140
Deobfuscate/Decode Files or Information
GroupAPT28

An APT28 macro uses the command certutil -decode to decode contents of a .txt file storing the base64 encoded payload.

T1218.011
Rundll32
GroupAPT28

APT28 executed CHOPSTICK by using rundll32 commands such as rundll32.exe “C:\Windows\twain_64.dll”. APT28 also executed a .dll for a first stage dropper using rundll32.exe. An APT28 loader Trojan saved a batch script that uses rundll32 to execute a DLL payload.

T1559.002
Dynamic Data Exchange
GroupAPT28

APT28 has delivered JHUHUGIT and Koadic by executing PowerShell commands through DDE in Word documents.

T1564.003
Hidden Window
GroupAPT28

APT28 has used the WindowStyle parameter to conceal PowerShell windows.

T1566.001
Spearphishing Attachment
GroupAPT28

APT28 sent spearphishing emails containing malicious Microsoft Office and RAR attachments.

T1588.002
Tool
GroupAPT28

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

T1680
Local Storage Discovery
MalwareZebrocy

Zebrocy collects the serial number for the storage volume C:\.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.