Marvi, A. et al.. (2023, March 16). Fortinet Zero-Day and Custom Malware Used by Suspected Chinese Actor in Espionage Operation. Retrieved March 22, 2023.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareCASTLETAP | CASTLETAP can execute a C2 command to transfer files from victim machines. |
| T1021.004 SSH |
GroupUNC3886 | UNC3886 has established remote SSH access to targeted ESXi hosts. |
| T1036.004 Masquerade Task or Service |
GroupUNC3886 | UNC3886 has named a file ‘fgfm’ in an attempt to disguise it as the legitimate service ‘fgfmd’ which facilitates communication between FortiManager and the FortiGate firewall. |
| T1037 Boot or Logon Initialization Scripts |
GroupUNC3886 | UNC3886 has attempted to bypass digital signature verification checks at startup by adding a command to the startup config `/etc/init.d/localnet` within the rootfs.gz archive of both FortiManager and FortiAnalyzer devices. |
| T1040 Network Sniffing |
MalwareCASTLETAP | CASTLETAP has the ability to create a raw promiscuous socket to sniff network traffic. |
| T1059.004 Unix Shell |
MalwareCASTLETAP | CASTLETAP has the ability to spawn BusyBox command shell in victim environments. |
| T1059.006 Python |
MalwareTHINCRUST | THINCRUST can use Python scripts for command execution. |
| T1070.004 File Deletion |
GroupUNC3886 | UNC3886 has used the the esxcli command line to remove files created by malicious vSphere Installation Bundles from disk. |
| T1070.007 Clear Network Connection History and Configurations |
GroupUNC3886 | UNC3886 has cleared specific events that contained the threat actor’s IP address from multiple log sources. |
| T1071.001 Web Protocols |
MalwareTHINCRUST | THINCRUST can use HTTP POST requests in C2 communications. |
| T1095 Non-Application Layer Protocol |
GroupUNC3886 | UNC3886 has deployed backdoors that communicate over TCP to compromised network devices and over VMCI to ESXi hosts. |
| T1095 Non-Application Layer Protocol |
MalwareREPTILE | REPTILE can communicate using TLS over raw TCP. |
| T1105 Ingress Tool Transfer |
MalwareCASTLETAP | CASTLETAP can transfer files to compromised network devices. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareCASTLETAP | CASTLETAP can filter and deobfuscate an XOR encrypted activation string in the payload of an ICMP echo request. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareTHINCRUST | THINCRUST can deobfuscate RSA encrypted C2 commands received through the DEVICEID cookie. |
| T1190 Exploit Public-Facing Application |
GroupUNC3886 | UNC3886 has exploited CVE-2022-42475 in FortiOS SSL VPNs to obtain access. |
| T1205 Traffic Signaling |
MalwareREPTILE | The REPTILE reverse shell component can listen for a specialized packet in TCP, UDP, or ICMP for activation. |
| T1205 Traffic Signaling |
GroupUNC3886 | UNC3886 has used the TABLEFLIP traffic redirection utility to listen for specialized command packets on compromised FortiManager devices. |
| T1205.001 Port Knocking |
GroupUNC3886 | UNC3886 maintained persistence on FortiGate Firewalls through ICMP port knocking. |
| T1205.002 Socket Filters |
MalwareCASTLETAP | CASTLETAP can listen for a specialized ICMP packet for activation on compromised network devices. |
| T1505.006 vSphere Installation Bundles |
GroupUNC3886 | UNC3886 has used vSphere Installation Bundles (VIBs) to install malware and establish persistence across ESXi hypervisors. |
| T1554 Compromise Host Software Binary |
GroupUNC3886 | UNC3886 has trojanized Fortinet firmware and replaced the legitimate `/usr/bin/tac_plus` TACACS+ daemon for Linux with a malicious version containing credential logging functionality. |
| T1564.011 Ignore Process Interrupts |
GroupUNC3886 | UNC3886 modified the startup file `/etc/init.d/localnet` to execute the line `nohup /bin/support &` so the script would run when the system was rebooted. |
| T1573.001 Symmetric Cryptography |
MalwareTHINCRUST | THINCRUST can process RSA encryted C2 commands. |
| T1573.001 Symmetric Cryptography |
MalwareCASTLETAP | CASTLETAP can receive a 9-byte XOR encrypted activation string in the payload of an ICMP echo request packet. |
| T1573.002 Asymmetric Cryptography |
MalwareCASTLETAP | CASTLETAP can initiate a C2 connection over an SSL socket. |
| T1573.002 Asymmetric Cryptography |
MalwareREPTILE | REPTILE can use TLS over raw TCP for secure C2. |
| T1587.001 Malware |
GroupUNC3886 | UNC3886 has deployed custom malware families on Fortinet and VMware systems. |
| T1587.004 Exploits |
GroupUNC3886 | UNC3886 has used zero-day vulnerabilities CVE-2022-41328 against FortiOS and CVE-2023-20867 and CVE-2023-34048 against VMware vCenter. |
| T1675 ESXi Administration Command |
GroupUNC3886 | UNC3886 used `vmtoolsd.exe` to run commands on guest virtual machines from a compromised ESXi host. |
| T1685 Disable or Modify Tools |
GroupUNC3886 | UNC3886 has disabled OpenSSL digital signature verification of system files through corruption of boot files. |
| T1686 Disable or Modify System Firewall |
MalwareTHINCRUST | THINCRUST can use the Django python module "django.views.decorators.csrf” along with the decorator “csrf_exempt” within victim firewalls to disable cross-site request forgery protections. |
| T1686 Disable or Modify System Firewall |
GroupUNC3886 | UNC3886 has used the TABLEFLIP traffic redirection utility and the esxcli command line to modify firewall rules. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.