ATT&CKReferencesKaspersky Cloud Atlas December 2014

Kaspersky Cloud Atlas December 2014

GReAT. (2014, December 10). Cloud Atlas: RedOctober APT is back in style. Retrieved May 8, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples11

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
GroupInception

Inception has encrypted malware payloads dropped on victim machines with AES and RC4 encryption.

T1059.001
PowerShell
GroupInception

Inception has used PowerShell to execute malicious commands and payloads.

T1059.005
Visual Basic
GroupInception

Inception has used VBScript to execute malicious commands and payloads.

T1071.001
Web Protocols
GroupInception

Inception has used HTTP, HTTPS, and WebDav in network communications.

T1102
Web Service
GroupInception

Inception has incorporated at least five different cloud service providers into their C2 infrastructure including CloudMe.

T1203
Exploitation for Client Execution
GroupInception

Inception has exploited CVE-2012-0158, CVE-2014-1761, CVE-2017-11882 and CVE-2018-0802 for execution.

T1204.002
Malicious File
GroupInception

Inception lured victims into clicking malicious files for machine reconnaissance and to execute malware.

T1218.010
Regsvr32
GroupInception

Inception has ensured persistence at system boot by setting the value regsvr32 %path%\ctfmonrn.dll /s.

T1547.001
Registry Run Keys / Startup Folder
GroupInception

Inception has maintained persistence by modifying Registry run key value
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\.

T1566.001
Spearphishing Attachment
GroupInception

Inception has used weaponized documents attached to spearphishing emails for reconnaissance and initial compromise.

T1573.001
Symmetric Cryptography
GroupInception

Inception has encrypted network communications with AES.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.