MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.003 NTDS |
GroupLAPSUS$ | LAPSUS$ has used Windows built-in tool `ntdsutil` to extract the Active Directory (AD) database. |
| T1003.006 DCSync |
GroupLAPSUS$ | LAPSUS$ has used DCSync attacks to gather credentials for privilege escalation routines. |
| T1005 Data from Local System |
GroupLAPSUS$ | LAPSUS$ uploaded sensitive files, information, and credentials from a targeted organization for extortion or public release. |
| T1068 Exploitation for Privilege Escalation |
GroupLAPSUS$ | LAPSUS$ has exploited unpatched vulnerabilities on internally accessible servers including JIRA, GitLab, and Confluence for privilege escalation. |
| T1069.002 Domain Groups |
GroupLAPSUS$ | LAPSUS$ has used the AD Explorer tool to enumerate groups on a victim's network. |
| T1078 Valid Accounts |
GroupLAPSUS$ | LAPSUS$ has used compromised credentials and/or session tokens to gain access into a victim's VPN, VDI, RDP, and IAMs. |
| T1078.004 Cloud Accounts |
GroupLAPSUS$ | LAPSUS$ has used compromised credentials to access cloud assets within a target organization. |
| T1087.002 Domain Account |
GroupLAPSUS$ | LAPSUS$ has used the AD Explorer tool to enumerate users on a victim's network. |
| T1090 Proxy |
GroupLAPSUS$ | LAPSUS$ has leverage NordVPN for its egress points when targeting intended victims. |
| T1098.003 Additional Cloud Roles |
GroupLAPSUS$ | LAPSUS$ has added the global admin role to accounts they have created in the targeted organization's cloud instances. |
| T1111 Multi-Factor Authentication Interception |
GroupLAPSUS$ | LAPSUS$ has replayed stolen session token and passwords to trigger simple-approval MFA prompts in hope of the legitimate user will grant necessary approval. |
| T1114.003 Email Forwarding Rule |
GroupLAPSUS$ | LAPSUS$ has set an Office 365 tenant level mail transport rule to send all mail in and out of the targeted organization to the newly created account. |
| T1133 External Remote Services |
GroupLAPSUS$ | LAPSUS$ has gained access to internet-facing systems and applications, including virtual private network (VPN), remote desktop protocol (RDP), and virtual desktop infrastructure (VDI) including Citrix. |
| T1136.003 Cloud Account |
GroupLAPSUS$ | LAPSUS$ has created global admin accounts in the targeted organization's cloud instances to gain persistence. |
| T1199 Trusted Relationship |
GroupLAPSUS$ | LAPSUS$ has accessed internet-facing identity providers such as Azure Active Directory and Okta to target specific organizations. |
| T1204 User Execution |
GroupLAPSUS$ | LAPSUS$ has recruited target organization employees or contractors who provide credentials and approve an associated MFA prompt, or install remote management software onto a corporate workstation, allowing LAPSUS$ to take control of an authenticated system. |
| T1213.001 Confluence |
GroupLAPSUS$ | LAPSUS$ has searched a victim's network for collaboration platforms like Confluence and JIRA to discover further high-privilege account credentials. |
| T1213.002 Sharepoint |
GroupLAPSUS$ | LAPSUS$ has searched a victim's network for collaboration platforms like SharePoint to discover further high-privilege account credentials. |
| T1213.003 Code Repositories |
GroupLAPSUS$ | LAPSUS$ has searched a victim's network for code repositories like GitLab and GitHub to discover further high-privilege account credentials. |
| T1213.005 Messaging Applications |
GroupLAPSUS$ | LAPSUS$ has searched a victim's network for organization collaboration channels like MS Teams or Slack to discover further high-privilege account credentials. |
| T1485 Data Destruction |
GroupLAPSUS$ | LAPSUS$ has deleted the target's systems and resources both on-premises and in the cloud. |
| T1531 Account Access Removal |
GroupLAPSUS$ | LAPSUS$ has removed a targeted organization's global admin accounts to lock the organization out of all access. |
| T1552.008 Chat Messages |
GroupLAPSUS$ | LAPSUS$ has targeted various collaboration tools like Slack, Teams, JIRA, Confluence, and others to hunt for exposed credentials to support privilege escalation and lateral movement. |
| T1555.003 Credentials from Web Browsers |
GroupLAPSUS$ | LAPSUS$ has obtained passwords and session tokens with the use of the Redline password stealer. |
| T1578.002 Create Cloud Instance |
GroupLAPSUS$ | LAPSUS$ has created new virtual machines within the target's cloud environment after leveraging credential access to cloud assets. |
| T1578.003 Delete Cloud Instance |
GroupLAPSUS$ | LAPSUS$ has deleted the target's systems and resources in the cloud to trigger the organization's incident and crisis response process. |
| T1583.003 Virtual Private Server |
GroupLAPSUS$ | LAPSUS$ has used VPS hosting providers for infrastructure. |
| T1586.002 Email Accounts |
GroupLAPSUS$ | LAPSUS$ has payed employees, suppliers, and business partners of target organizations for credentials. |
| T1588.001 Malware |
GroupLAPSUS$ | LAPSUS$ acquired and used the Redline password stealer in their operations. |
| T1588.002 Tool |
GroupLAPSUS$ | LAPSUS$ has obtained tools such as RVTools and AD Explorer for their operations. |
| T1589 Gather Victim Identity Information |
GroupLAPSUS$ | LAPSUS$ has gathered detailed information of target employees to enhance their social engineering lures. |
| T1589.001 Credentials |
GroupLAPSUS$ | LAPSUS$ has gathered user identities and credentials to gain initial access to a victim's organization; the group has also called an organization's help desk to reset a target's credentials. |
| T1589.002 Email Addresses |
GroupLAPSUS$ | LAPSUS$ has gathered employee email addresses, including personal accounts, for social engineering and initial access efforts. |
| T1591.002 Business Relationships |
GroupLAPSUS$ | LAPSUS$ has gathered detailed knowledge of an organization's supply chain relationships. |
| T1591.004 Identify Roles |
GroupLAPSUS$ | LAPSUS$ has gathered detailed knowledge of team structures within a target organization. |
| T1593.003 Code Repositories |
GroupLAPSUS$ | LAPSUS$ has searched public code repositories for exposed credentials. |
| T1597.002 Purchase Technical Data |
GroupLAPSUS$ | LAPSUS$ has purchased credentials and session tokens from criminal underground forums. |
| T1598.004 Spearphishing Voice |
GroupLAPSUS$ | LAPSUS$ has called victims' help desk to convince the support personnel to reset a privileged account’s credentials. |
| T1621 Multi-Factor Authentication Request Generation |
GroupLAPSUS$ | LAPSUS$ has spammed target users with MFA prompts in the hope that the legitimate user will grant necessary approval. |
| T1684.001 Impersonation |
GroupLAPSUS$ | LAPSUS$ has called victims' help desk and impersonated legitimate users with previously gathered information in order to gain access to privileged accounts. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.