ATT&CKReferencesClearSky Wilted Tulip July 2017

ClearSky Wilted Tulip July 2017

ClearSky Cyber Security and Trend Micro. (2017, July). Operation Wilted Tulip: Exposing a cyber espionage apparatus. Retrieved August 21, 2017.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software2

Campaigns0

None recorded.

Procedure examples17

TechniqueUsed byProcedure example
T1053.005
Scheduled Task
MalwareMatryoshka

Matryoshka can establish persistence by adding a Scheduled Task named "Microsoft Boost Kernel Optimization".

T1056.001
Keylogging
MalwareMatryoshka

Matryoshka is capable of keylogging.

T1059
Command and Scripting Interpreter
MalwareMatryoshka

Matryoshka is capable of providing Meterpreter shell access.

T1059.001
PowerShell
GroupCopyKittens

CopyKittens has used PowerShell Empire.

T1059.003
Windows Command Shell
MalwareTDTESS

TDTESS provides a reverse shell on the victim.

T1070.004
File Deletion
MalwareTDTESS

TDTESS creates then deletes log files during installation of itself as a service.

T1070.006
Timestomp
MalwareTDTESS

After creating a new service for persistence, TDTESS sets the file creation time for the service to the creation time of the victim's legitimate svchost.exe file.

T1071.004
DNS
MalwareMatryoshka

Matryoshka uses DNS for C2.

T1105
Ingress Tool Transfer
MalwareTDTESS

TDTESS has a command to download and execute an additional file.

T1113
Screen Capture
MalwareMatryoshka

Matryoshka is capable of performing screen captures.

T1218.011
Rundll32
GroupCopyKittens

CopyKittens uses rundll32 to load various tools on victims, including a lateral movement tool named Vminst, Cobalt Strike, and shellcode.

T1543.003
Windows Service
MalwareTDTESS

If running as administrator, TDTESS installs itself as a new service named bmwappushservice to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareMatryoshka

Matryoshka can establish persistence by adding Registry Run keys.

T1553.002
Code Signing
GroupCopyKittens

CopyKittens digitally signed an executable with a stolen certificate from legitimate company AI Squared.

T1555
Credentials from Password Stores
MalwareMatryoshka

Matryoshka is capable of stealing Outlook passwords.

T1560.001
Archive via Utility
GroupCopyKittens

CopyKittens uses ZPP, a .NET console program, to compress files with ZIP.

T1564.003
Hidden Window
GroupCopyKittens

CopyKittens has used -w hidden and -windowstyle hidden to conceal PowerShell windows.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.