ATT&CKReferencesCybersecurity Advisory GRU Brute Force Campaign July 2021

Cybersecurity Advisory GRU Brute Force Campaign July 2021

NSA, CISA, FBI, NCSC. (2021, July). Russian GRU Conducting Global Brute Force Campaign to Compromise Enterprise and Cloud Environments. Retrieved July 26, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples26

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupAPT28

APT28 regularly deploys both publicly available (ex: Mimikatz) and custom password retrieval tools on victims. They have also dumped the LSASS process memory using the MiniDump function.

T1003.003
NTDS
GroupAPT28

APT28 has used the ntdsutil.exe utility to export the Active Directory database for credential access.

T1005
Data from Local System
GroupAPT28

APT28 has retrieved internal documents from machines inside victim environments, including by using Forfiles to stage documents before exfiltration.

T1021.002
SMB/Windows Admin Shares
GroupAPT28

APT28 has mapped network drives using Net and administrator credentials.

T1030
Data Transfer Size Limits
GroupAPT28

APT28 has split archived exfiltration files into chunks smaller than 1MB.

T1036
Masquerading
GroupAPT28

APT28 has renamed the WinRAR utility to avoid detection.

T1036.005
Match Legitimate Resource Name or Location
GroupAPT28

APT28 has changed extensions on files containing exfiltrated data to make them appear benign, and renamed a web shell instance to appear as a legitimate OWA page.

T1039
Data from Network Shared Drive
GroupAPT28

APT28 has collected files from network shared drives.

T1048.002
Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
GroupAPT28

APT28 has exfiltrated archives of collected data previously staged on a target's OWA server via HTTPS.

T1059.001
PowerShell
GroupAPT28

APT28 downloads and executes PowerShell scripts and performs PowerShell commands.

T1071.001
Web Protocols
GroupAPT28

Later implants used by APT28, such as CHOPSTICK, use a blend of HTTP, HTTPS, and other legitimate channels for C2, depending on module configuration.

T1071.003
Mail Protocols
GroupAPT28

APT28 has used IMAP, POP3, and SMTP for a communication channel in various implants, including using self-registered Google Mail accounts and later compromised email servers of its victims.

T1074.002
Remote Data Staging
GroupAPT28

APT28 has staged archives of collected data on a target's Outlook Web Access (OWA) server.

T1078
Valid Accounts
GroupAPT28

APT28 has used legitimate credentials to gain initial access, maintain access, and exfiltrate data from a victim network. The group has specifically used credentials stolen through a spearphishing email to login to the DCCC network. The group has also leveraged default manufacturer's passwords to gain initial access to corporate networks via IoT devices such as a VOIP phone, printer, and video decoder.

T1078.004
Cloud Accounts
GroupAPT28

APT28 has used compromised Office 365 service accounts with Global Administrator privileges to collect email from user inboxes.

T1098.002
Additional Email Delegate Permissions
GroupAPT28

APT28 has used a Powershell cmdlet to grant the ApplicationImpersonation role to a compromised account.

T1105
Ingress Tool Transfer
GroupAPT28

APT28 has downloaded additional files, including by using a first-stage downloader to contact the C2 server to obtain the second-stage implant.

T1110.001
Password Guessing
GroupAPT28

APT28 has used a brute-force/password-spray tooling that operated in two modes: in brute-force mode it typically sent over 300 authentication attempts per hour per targeted account over the course of several hours or days. APT28 has also used a Kubernetes cluster to conduct distributed, large-scale password guessing attacks.

T1110.003
Password Spraying
GroupAPT28

APT28 has used a brute-force/password-spray tooling that operated in two modes: in password-spraying mode it conducted approximately four authentication attempts per hour per targeted account over the course of several days or weeks. APT28 has also used a Kubernetes cluster to conduct distributed, large-scale password spray attacks.

T1114.002
Remote Email Collection
GroupAPT28

APT28 has collected emails from victim Microsoft Exchange servers.

T1133
External Remote Services
GroupAPT28

APT28 has used Tor and a variety of commercial VPN services to route brute force authentication attempts.

T1190
Exploit Public-Facing Application
GroupAPT28

APT28 has used a variety of public exploits, including CVE 2020-0688 and CVE 2020-17144, to gain execution on vulnerable Microsoft Exchange; they have also conducted SQL injection attacks against external websites.

T1213
Data from Information Repositories
GroupAPT28

APT28 has collected files from various information repositories.

T1218.011
Rundll32
GroupAPT28

APT28 executed CHOPSTICK by using rundll32 commands such as rundll32.exe “C:\Windows\twain_64.dll”. APT28 also executed a .dll for a first stage dropper using rundll32.exe. An APT28 loader Trojan saved a batch script that uses rundll32 to execute a DLL payload.

T1505.003
Web Shell
GroupAPT28

APT28 has used a modified and obfuscated version of the reGeorg web shell to maintain persistence on a target's Outlook Web Access (OWA) server.

T1560.001
Archive via Utility
GroupAPT28

APT28 has used a variety of utilities, including WinRAR, to archive collected data with password protection.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.