ATT&CKReferencesMSTIC DEV-0537 Mar 2022

MSTIC DEV-0537 Mar 2022

MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples40

TechniqueUsed byProcedure example
T1003.003
NTDS
GroupLAPSUS$

LAPSUS$ has used Windows built-in tool `ntdsutil` to extract the Active Directory (AD) database.

T1003.006
DCSync
GroupLAPSUS$

LAPSUS$ has used DCSync attacks to gather credentials for privilege escalation routines.

T1005
Data from Local System
GroupLAPSUS$

LAPSUS$ uploaded sensitive files, information, and credentials from a targeted organization for extortion or public release.

T1068
Exploitation for Privilege Escalation
GroupLAPSUS$

LAPSUS$ has exploited unpatched vulnerabilities on internally accessible servers including JIRA, GitLab, and Confluence for privilege escalation.

T1069.002
Domain Groups
GroupLAPSUS$

LAPSUS$ has used the AD Explorer tool to enumerate groups on a victim's network.

T1078
Valid Accounts
GroupLAPSUS$

LAPSUS$ has used compromised credentials and/or session tokens to gain access into a victim's VPN, VDI, RDP, and IAMs.

T1078.004
Cloud Accounts
GroupLAPSUS$

LAPSUS$ has used compromised credentials to access cloud assets within a target organization.

T1087.002
Domain Account
GroupLAPSUS$

LAPSUS$ has used the AD Explorer tool to enumerate users on a victim's network.

T1090
Proxy
GroupLAPSUS$

LAPSUS$ has leverage NordVPN for its egress points when targeting intended victims.

T1098.003
Additional Cloud Roles
GroupLAPSUS$

LAPSUS$ has added the global admin role to accounts they have created in the targeted organization's cloud instances.

T1111
Multi-Factor Authentication Interception
GroupLAPSUS$

LAPSUS$ has replayed stolen session token and passwords to trigger simple-approval MFA prompts in hope of the legitimate user will grant necessary approval.

T1114.003
Email Forwarding Rule
GroupLAPSUS$

LAPSUS$ has set an Office 365 tenant level mail transport rule to send all mail in and out of the targeted organization to the newly created account.

T1133
External Remote Services
GroupLAPSUS$

LAPSUS$ has gained access to internet-facing systems and applications, including virtual private network (VPN), remote desktop protocol (RDP), and virtual desktop infrastructure (VDI) including Citrix.

T1136.003
Cloud Account
GroupLAPSUS$

LAPSUS$ has created global admin accounts in the targeted organization's cloud instances to gain persistence.

T1199
Trusted Relationship
GroupLAPSUS$

LAPSUS$ has accessed internet-facing identity providers such as Azure Active Directory and Okta to target specific organizations.

T1204
User Execution
GroupLAPSUS$

LAPSUS$ has recruited target organization employees or contractors who provide credentials and approve an associated MFA prompt, or install remote management software onto a corporate workstation, allowing LAPSUS$ to take control of an authenticated system.

T1213.001
Confluence
GroupLAPSUS$

LAPSUS$ has searched a victim's network for collaboration platforms like Confluence and JIRA to discover further high-privilege account credentials.

T1213.002
Sharepoint
GroupLAPSUS$

LAPSUS$ has searched a victim's network for collaboration platforms like SharePoint to discover further high-privilege account credentials.

T1213.003
Code Repositories
GroupLAPSUS$

LAPSUS$ has searched a victim's network for code repositories like GitLab and GitHub to discover further high-privilege account credentials.

T1213.005
Messaging Applications
GroupLAPSUS$

LAPSUS$ has searched a victim's network for organization collaboration channels like MS Teams or Slack to discover further high-privilege account credentials.

T1485
Data Destruction
GroupLAPSUS$

LAPSUS$ has deleted the target's systems and resources both on-premises and in the cloud.

T1531
Account Access Removal
GroupLAPSUS$

LAPSUS$ has removed a targeted organization's global admin accounts to lock the organization out of all access.

T1552.008
Chat Messages
GroupLAPSUS$

LAPSUS$ has targeted various collaboration tools like Slack, Teams, JIRA, Confluence, and others to hunt for exposed credentials to support privilege escalation and lateral movement.

T1555.003
Credentials from Web Browsers
GroupLAPSUS$

LAPSUS$ has obtained passwords and session tokens with the use of the Redline password stealer.

T1578.002
Create Cloud Instance
GroupLAPSUS$

LAPSUS$ has created new virtual machines within the target's cloud environment after leveraging credential access to cloud assets.

T1578.003
Delete Cloud Instance
GroupLAPSUS$

LAPSUS$ has deleted the target's systems and resources in the cloud to trigger the organization's incident and crisis response process.

T1583.003
Virtual Private Server
GroupLAPSUS$

LAPSUS$ has used VPS hosting providers for infrastructure.

T1586.002
Email Accounts
GroupLAPSUS$

LAPSUS$ has payed employees, suppliers, and business partners of target organizations for credentials.

T1588.001
Malware
GroupLAPSUS$

LAPSUS$ acquired and used the Redline password stealer in their operations.

T1588.002
Tool
GroupLAPSUS$

LAPSUS$ has obtained tools such as RVTools and AD Explorer for their operations.

T1589
Gather Victim Identity Information
GroupLAPSUS$

LAPSUS$ has gathered detailed information of target employees to enhance their social engineering lures.

T1589.001
Credentials
GroupLAPSUS$

LAPSUS$ has gathered user identities and credentials to gain initial access to a victim's organization; the group has also called an organization's help desk to reset a target's credentials.

T1589.002
Email Addresses
GroupLAPSUS$

LAPSUS$ has gathered employee email addresses, including personal accounts, for social engineering and initial access efforts.

T1591.002
Business Relationships
GroupLAPSUS$

LAPSUS$ has gathered detailed knowledge of an organization's supply chain relationships.

T1591.004
Identify Roles
GroupLAPSUS$

LAPSUS$ has gathered detailed knowledge of team structures within a target organization.

T1593.003
Code Repositories
GroupLAPSUS$

LAPSUS$ has searched public code repositories for exposed credentials.

T1597.002
Purchase Technical Data
GroupLAPSUS$

LAPSUS$ has purchased credentials and session tokens from criminal underground forums.

T1598.004
Spearphishing Voice
GroupLAPSUS$

LAPSUS$ has called victims' help desk to convince the support personnel to reset a privileged account’s credentials.

T1621
Multi-Factor Authentication Request Generation
GroupLAPSUS$

LAPSUS$ has spammed target users with MFA prompts in the hope that the legitimate user will grant necessary approval.

T1684.001
Impersonation
GroupLAPSUS$

LAPSUS$ has called victims' help desk and impersonated legitimate users with previously gathered information in order to gain access to privileged accounts.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.