ATT&CKReferencesProofpoint Operation Transparent Tribe March 2016

Proofpoint Operation Transparent Tribe March 2016

Huss, D. (2016, March 1). Operation Transparent Tribe. Retrieved June 8, 2016.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software2

Campaigns0

None recorded.

Procedure examples40

TechniqueUsed byProcedure example
T1012
Query Registry
MalwareCrimson

Crimson can check the Registry for the presence of HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\last_edate to determine how long it has been installed on a host.

T1016
System Network Configuration Discovery
MalwareCrimson

Crimson contains a command to collect the victim MAC address and LAN IP.

T1020
Automated Exfiltration
MalwarePeppy

Peppy has the ability to automatically exfiltrate files and keylogs.

T1025
Data from Removable Media
MalwareCrimson

Crimson contains a module to collect data from removable drives.

T1027.013
Encrypted/Encoded File
GroupTransparent Tribe

Transparent Tribe has dropped encoded executables on compromised hosts.

T1033
System Owner/User Discovery
MalwareCrimson

Crimson can identify the user on a targeted system.

T1056.001
Keylogging
MalwarePeppy

Peppy can log keystrokes on compromised hosts.

T1056.001
Keylogging
MalwareCrimson

Crimson can use a module to perform keylogging on compromised hosts.

T1057
Process Discovery
MalwareCrimson

Crimson contains a command to list processes.

T1059.003
Windows Command Shell
MalwarePeppy

Peppy has the ability to execute shell commands.

T1059.005
Visual Basic
GroupTransparent Tribe

Transparent Tribe has crafted VBS-based malicious documents.

T1070.004
File Deletion
MalwareCrimson

Crimson has the ability to delete files from a compromised host.

T1071.001
Web Protocols
MalwareCrimson

Crimson can use a HTTP GET request to download its final payload.

T1071.001
Web Protocols
MalwarePeppy

Peppy can use HTTP to communicate with C2.

T1082
System Information Discovery
MalwareCrimson

Crimson contains a command to collect the victim PC name and operating system.

T1083
File and Directory Discovery
MalwarePeppy

Peppy can identify specific files for exfiltration.

T1083
File and Directory Discovery
MalwareCrimson

Crimson contains commands to list files and directories, as well as search for files matching certain extensions from a defined list.

T1095
Non-Application Layer Protocol
MalwareCrimson

Crimson uses a custom TCP protocol for C2.

T1105
Ingress Tool Transfer
MalwareCrimson

Crimson contains a command to retrieve files from its C2 server.

T1105
Ingress Tool Transfer
MalwarePeppy

Peppy can download and execute remote files.

T1112
Modify Registry
MalwareCrimson

Crimson can set a Registry key to determine how long it has been installed and possibly to indicate the version number.

T1113
Screen Capture
MalwarePeppy

Peppy can take screenshots on targeted systems.

T1113
Screen Capture
MalwareCrimson

Crimson contains a command to perform screen captures.

T1114.001
Local Email Collection
MalwareCrimson

Crimson contains a command to collect and exfiltrate emails from Outlook.

T1120
Peripheral Device Discovery
MalwareCrimson

Crimson has the ability to discover pluggable/removable drives to extract files from.

T1125
Video Capture
MalwareCrimson

Crimson can capture webcam video on targeted systems.

T1140
Deobfuscate/Decode Files or Information
MalwareCrimson

Crimson can decode its encoded PE file prior to execution.

T1189
Drive-by Compromise
GroupTransparent Tribe

Transparent Tribe has used websites with malicious hyperlinks and iframes to infect targeted victims with Crimson, njRAT, and other malicious tools.

T1203
Exploitation for Client Execution
GroupTransparent Tribe

Transparent Tribe has crafted malicious files to exploit CVE-2012-0158 and CVE-2010-3333 for execution.

T1204.002
Malicious File
GroupTransparent Tribe

Transparent Tribe has used weaponized documents in e-mail to compromise targeted systems.

T1497.003
Time Based Checks
MalwareCrimson

Crimson can determine when it has been installed on a host for at least 15 days before downloading the final payload.

T1518.001
Security Software Discovery
MalwareCrimson

Crimson contains a command to collect information about anti-virus software on the victim.

T1547.001
Registry Run Keys / Startup Folder
MalwareCrimson

Crimson can add Registry run keys for persistence.

T1555.003
Credentials from Web Browsers
MalwareCrimson

Crimson contains a module to steal credentials from Web browsers on the victim machine.

T1566.001
Spearphishing Attachment
GroupTransparent Tribe

Transparent Tribe has sent spearphishing e-mails with attachments to deliver malicious payloads.

T1568
Dynamic Resolution
GroupTransparent Tribe

Transparent Tribe has used dynamic DNS services to set up C2.

T1583.001
Domains
GroupTransparent Tribe

Transparent Tribe has registered domains to mimic file sharing, government, defense, and research websites for use in targeted campaigns.

T1584.001
Domains
GroupTransparent Tribe

Transparent Tribe has compromised domains for use in targeted malicious campaigns.

T1608.004
Drive-by Target
GroupTransparent Tribe

Transparent Tribe has set up websites with malicious hyperlinks and iframes to infect targeted victims with Crimson, njRAT, and other malicious tools.

T1680
Local Storage Discovery
MalwareCrimson

Crimson contains a command to collect disk drive information.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.