ATT&CKReferencesKaspersky CactusPete Aug 2020

Kaspersky CactusPete Aug 2020

Zykov, K. (2020, August 13). CactusPete APT group’s updated Bisonal backdoor. Retrieved May 5, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples13

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareBisonal

Bisonal can execute ipconfig on the victim’s machine.

T1057
Process Discovery
MalwareBisonal

Bisonal can obtain a list of running processes on the victim’s machine.

T1059.003
Windows Command Shell
MalwareBisonal

Bisonal has launched cmd.exe and used the ShellExecuteW() API function to execute commands on the system.

T1070.004
File Deletion
MalwareBisonal

Bisonal will delete its dropper and VBS scripts from the victim’s machine.

T1071.001
Web Protocols
MalwareBisonal

Bisonal has used HTTP for C2 communications.

T1082
System Information Discovery
MalwareBisonal

Bisonal has used commands and API calls to gather system information.

T1083
File and Directory Discovery
MalwareBisonal

Bisonal can retrieve a file listing from the system.

T1105
Ingress Tool Transfer
MalwareBisonal

Bisonal has the capability to download files to execute on the victim’s machine.

T1124
System Time Discovery
MalwareBisonal

Bisonal can check the system time set on the infected host.

T1132.001
Standard Encoding
MalwareBisonal

Bisonal has encoded binary data with Base64 and ASCII.

T1203
Exploitation for Client Execution
GroupTonto Team

Tonto Team has exploited Microsoft vulnerabilities, including CVE-2018-0798, CVE-2018-8174, CVE-2018-0802, CVE-2017-11882, CVE-2019-9489 CVE-2020-8468, and CVE-2018-0798 to enable execution of their delivered malicious payloads.

T1497.003
Time Based Checks
MalwareBisonal

Bisonal has checked if the malware is running in a virtual environment with the anti-debug function GetTickCount() to compare the timing.

T1573.001
Symmetric Cryptography
MalwareBisonal

Bisonal variants reported on in 2014 and 2015 used a simple XOR cipher for C2. Some Bisonal samples encrypt C2 communications with RC4.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.