ATT&CKReferencesKaspersky MoleRATs April 2019

Kaspersky MoleRATs April 2019

GReAT. (2019, April 10). Gaza Cybergang Group1, operation SneakyPastes. Retrieved May 13, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples20

TechniqueUsed byProcedure example
T1027.015
Compression
GroupMolerats

Molerats has delivered compressed executables within ZIP files to victims.

T1041
Exfiltration Over C2 Channel
MalwareDustySky

DustySky has exfiltrated data to the C2 server.

T1057
Process Discovery
MalwareDustySky

DustySky collects information about running processes from victims.

T1059.001
PowerShell
GroupMolerats

Molerats used PowerShell implants on target machines.

T1059.005
Visual Basic
GroupMolerats

Molerats used various implants, including those built with VBScript, on target machines.

T1059.007
JavaScript
GroupMolerats

Molerats used various implants, including those built with JS, on target machines.

T1070.004
File Deletion
MalwareDustySky

DustySky can delete files it creates from the infected system.

T1074.001
Local Data Staging
MalwareDustySky

DustySky created folders in temp directories to host collected files before exfiltration.

T1083
File and Directory Discovery
MalwareDustySky

DustySky scans the victim for files that contain certain keywords and document types including PDF, DOC, DOCX, XLS, and XLSX, from a list that is obtained from the C2 as a text file. It can also identify logical drives for the infected machine.

T1105
Ingress Tool Transfer
GroupMolerats

Molerats used executables to download malicious files from different sources.

T1113
Screen Capture
MalwareDustySky

DustySky captures PNG screenshots of the main screen.

T1120
Peripheral Device Discovery
MalwareDustySky

DustySky can detect connected USB devices.

T1140
Deobfuscate/Decode Files or Information
GroupMolerats

Molerats decompresses ZIP files once on the victim machine.

T1204.001
Malicious Link
GroupMolerats

Molerats has sent malicious links via email trick users into opening a RAR archive and running an executable.

T1204.002
Malicious File
GroupMolerats

Molerats has sent malicious files via email that tricked users into clicking Enable Content to run an embedded macro and to download malicious archives.

T1518
Software Discovery
MalwareDustySky

DustySky lists all installed software for the infected machine.

T1547.001
Registry Run Keys / Startup Folder
GroupMolerats

Molerats saved malicious files within the AppData and Startup folders to maintain persistence.

T1560.001
Archive via Utility
MalwareDustySky

DustySky can compress files via RAR while staging data to be exfiltrated.

T1566.001
Spearphishing Attachment
GroupMolerats

Molerats has sent phishing emails with malicious Microsoft Word and PDF attachments.

T1566.002
Spearphishing Link
GroupMolerats

Molerats has sent phishing emails with malicious links included.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.