FireEye Labs. (2015, April). APT30 AND THE MECHANICS OF A LONG-RUNNING CYBER ESPIONAGE OPERATION. Retrieved November 17, 2024.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareFLASHFLOOD | FLASHFLOOD searches for interesting files (either a default or customized set of file extensions) on the local system. FLASHFLOOD will scan the My Recent Documents, Desktop, Temporary Internet Files, and TEMP directories. FLASHFLOOD also collects information stored in the Windows Address Book. |
| T1008 Fallback Channels |
MalwareNETEAGLE | NETEAGLE will attempt to detect if the infected host is configured to a proxy. If so, NETEAGLE will send beacons via an HTTP POST request; otherwise it will send beacons via UDP/6000. |
| T1012 Query Registry |
MalwareBACKSPACE | BACKSPACE is capable of enumerating and making modifications to an infected system's Registry. |
| T1025 Data from Removable Media |
MalwareFLASHFLOOD | FLASHFLOOD searches for interesting files (either a default or customized set of file extensions) on removable media and copies them to a staging area. The default file types copied would include data copied to the drive by SPACESHIP. |
| T1041 Exfiltration Over C2 Channel |
MalwareNETEAGLE | NETEAGLE is capable of reading files over the C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareBACKSPACE | Adversaries can direct BACKSPACE to upload files to the C2 Server. |
| T1052.001 Exfiltration over USB |
MalwareSPACESHIP | SPACESHIP copies staged data to removable drives when they are inserted into the system. |
| T1057 Process Discovery |
MalwareNETEAGLE | NETEAGLE can send process listings over the C2 channel. |
| T1057 Process Discovery |
MalwareBACKSPACE | BACKSPACE may collect information about running processes. |
| T1059.003 Windows Command Shell |
MalwareNETEAGLE | NETEAGLE allows adversaries to execute shell commands on the infected host. |
| T1059.003 Windows Command Shell |
MalwareBACKSPACE | Adversaries can direct BACKSPACE to execute from the command line on infected hosts, or have BACKSPACE create a reverse shell. |
| T1071.001 Web Protocols |
MalwareNETEAGLE | NETEAGLE will attempt to detect if the infected host is configured to a proxy. If so, NETEAGLE will send beacons via an HTTP POST request. NETEAGLE will also use HTTP to download resources that contain an IP address and Port Number pair to connect to for further C2. |
| T1071.001 Web Protocols |
MalwareBACKSPACE | BACKSPACE uses HTTP as a transport to communicate with its command server. |
| T1074.001 Local Data Staging |
MalwareFLASHFLOOD | FLASHFLOOD stages data it copies from the local system or removable drives in the "%WINDIR%\$NtUninstallKB885884$\" directory. |
| T1074.001 Local Data Staging |
MalwareSPACESHIP | SPACESHIP identifies files with certain extensions and copies them to a directory in the user's profile. |
| T1082 System Information Discovery |
MalwareBACKSPACE | During its initial execution, BACKSPACE extracts operating system information from the infected host. |
| T1083 File and Directory Discovery |
MalwareNETEAGLE | NETEAGLE allows adversaries to enumerate and modify the infected host's file system. It supports searching for directories, creating directories, listing directory contents, reading and writing to files, retrieving file attributes, and retrieving volume information. |
| T1083 File and Directory Discovery |
MalwareFLASHFLOOD | FLASHFLOOD searches for interesting files (either a default or customized set of file extensions) on the local system and removable media. |
| T1083 File and Directory Discovery |
MalwareSPACESHIP | SPACESHIP identifies files and directories for collection by searching for specific file extensions or file modification time. |
| T1083 File and Directory Discovery |
MalwareBACKSPACE | BACKSPACE allows adversaries to search for files. |
| T1090.001 Internal Proxy |
MalwareBACKSPACE | The "ZJ" variant of BACKSPACE allows "ZJ link" infections with Internet access to relay traffic from "ZJ listen" to a command server. |
| T1091 Replication Through Removable Media |
MalwareSHIPSHAPE | APT30 may have used the SHIPSHAPE malware to move onto air-gapped networks. SHIPSHAPE targets removable drives to spread to other systems by modifying the drive to use Autorun to execute or by hiding legitimate document files and copying an executable to the folder with the same name as the legitimate document. |
| T1095 Non-Application Layer Protocol |
MalwareNETEAGLE | If NETEAGLE does not detect a proxy configured on the infected machine, it will send beacons via UDP/6000. Also, after retrieving a C2 IP address and Port Number, NETEAGLE will initiate a TCP connection to this socket. The ensuing connection is a plaintext C2 channel in which commands are specified by DWORDs. |
| T1104 Multi-Stage Channels |
MalwareBACKSPACE | BACKSPACE attempts to avoid detection by checking a first stage command and control server to determine if it should connect to the second stage server, which performs "louder" interactions with the malware. |
| T1112 Modify Registry |
MalwareBACKSPACE | BACKSPACE is capable of deleting Registry keys, sub-keys, and values on a victim system. |
| T1132.002 Non-Standard Encoding |
MalwareBACKSPACE | Newer variants of BACKSPACE will encode C2 communications with a custom system. |
| T1204.002 Malicious File |
GroupAPT30 | APT30 has relied on users to execute malicious file attachments delivered via spearphishing emails. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareSHIPSHAPE | SHIPSHAPE achieves persistence by creating a shortcut in the Startup folder. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareBACKSPACE | BACKSPACE achieves persistence by creating a shortcut to itself in the CSIDL_STARTUP directory. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareFLASHFLOOD | FLASHFLOOD achieves persistence by making an entry in the Registry's Run key. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareNETEAGLE | The "SCOUT" variant of NETEAGLE achieves persistence by adding itself to the |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareSPACESHIP | SPACESHIP achieves persistence by creating a shortcut in the current user's Startup folder. |
| T1547.009 Shortcut Modification |
MalwareSHIPSHAPE | SHIPSHAPE achieves persistence by creating a shortcut in the Startup folder. |
| T1547.009 Shortcut Modification |
MalwareSPACESHIP | SPACESHIP achieves persistence by creating a shortcut in the current user's Startup folder. |
| T1547.009 Shortcut Modification |
MalwareBACKSPACE | BACKSPACE achieves persistence by creating a shortcut to itself in the CSIDL_STARTUP directory. |
| T1560.003 Archive via Custom Method |
MalwareFLASHFLOOD | FLASHFLOOD employs the same encoding scheme as SPACESHIP for data it stages. Data is compressed with zlib, and bytes are rotated four times before being XOR'ed with 0x23. |
| T1560.003 Archive via Custom Method |
MalwareSPACESHIP | Data SPACESHIP copies to the staging area is compressed with zlib. Bytes are rotated by four positions and XOR'ed with 0x23. |
| T1566.001 Spearphishing Attachment |
GroupAPT30 | APT30 has used spearphishing emails with malicious DOC attachments. |
| T1568 Dynamic Resolution |
MalwareNETEAGLE | NETEAGLE can use HTTP to download resources that contain an IP address and port number pair to connect to for C2. |
| T1573.001 Symmetric Cryptography |
MalwareNETEAGLE | NETEAGLE will decrypt resources it downloads with HTTP requests by using RC4 with the key "ScoutEagle." |
| T1686 Disable or Modify System Firewall |
MalwareBACKSPACE | The "ZR" variant of BACKSPACE will check to see if known host-based firewalls are installed on the infected systems. BACKSPACE will attempt to establish a C2 channel, then will examine open windows to identify a pop-up from the firewall software and will simulate a mouse-click to allow the connection to proceed. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.