ATT&CKReferencesSecureWorks BRONZE UNION June 2017

SecureWorks BRONZE UNION June 2017

Counter Threat Unit Research Team. (2017, June 27). BRONZE UNION Cyberespionage Persists Despite Disclosures. Retrieved July 13, 2017.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples20

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupThreat Group-3390

Threat Group-3390 actors have used a modified version of Mimikatz called Wrapikatz to dump credentials. They have also dumped credentials from domain controllers.

T1003.002
Security Account Manager
GroupThreat Group-3390

Threat Group-3390 actors have used gsecdump to dump credentials. They have also dumped credentials from domain controllers.

T1003.004
LSA Secrets
GroupThreat Group-3390

Threat Group-3390 actors have used gsecdump to dump credentials. They have also dumped credentials from domain controllers.

T1005
Data from Local System
GroupThreat Group-3390

Threat Group-3390 ran a command to compile an archive of file types of interest from the victim user's directories.

T1021.006
Windows Remote Management
GroupThreat Group-3390

Threat Group-3390 has used WinRM to enable remote execution.

T1049
System Network Connections Discovery
GroupThreat Group-3390

Threat Group-3390 has used `net use` and `netstat` to conduct internal discovery of systems. The group has also used `quser.exe` to identify existing RDP sessions on a victim.

T1059.001
PowerShell
GroupThreat Group-3390

Threat Group-3390 has used PowerShell for execution.

T1059.003
Windows Command Shell
GroupThreat Group-3390

Threat Group-3390 has used command-line interfaces for execution.

T1059.003
Windows Command Shell
MalwareChina Chopper

China Chopper's server component is capable of opening a command terminal.

T1068
Exploitation for Privilege Escalation
GroupThreat Group-3390

Threat Group-3390 has used CVE-2014-6324 and CVE-2017-0213 to escalate privileges.

T1070.004
File Deletion
GroupThreat Group-3390

Threat Group-3390 has deleted existing logs and exfiltrated file archives from a victim.

T1070.005
Network Share Connection Removal
GroupThreat Group-3390

Threat Group-3390 has detached network shares after exfiltrating files, likely to evade detection.

T1074.001
Local Data Staging
GroupThreat Group-3390

Threat Group-3390 has locally staged encrypted archives for later exfiltration efforts.

T1074.002
Remote Data Staging
GroupThreat Group-3390

Threat Group-3390 has moved staged encrypted archives to Internet-facing servers that had previously been compromised with China Chopper prior to exfiltration.

T1087.001
Local Account
GroupThreat Group-3390

Threat Group-3390 has used net user to conduct internal discovery of systems.

T1119
Automated Collection
GroupThreat Group-3390

Threat Group-3390 ran a command to compile an archive of file types of interest from the victim user's directories.

T1133
External Remote Services
GroupThreat Group-3390

Threat Group-3390 actors look for and use VPN profiles during an operation to access the network using external VPN services. Threat Group-3390 has also obtained OWA account credentials during intrusions that it subsequently used to attempt to regain access when evicted from a victim network.

T1560.002
Archive via Library
GroupThreat Group-3390

Threat Group-3390 has used RAR to compress, encrypt, and password-protect files prior to exfiltration.

T1574.001
DLL
GroupThreat Group-3390

Threat Group-3390 has performed DLL search order hijacking to execute their payload. Threat Group-3390 has also used DLL side-loading, including by using legitimate Kaspersky antivirus variants as well as `rc.exe`, a legitimate Microsoft Resource Compiler.

T1685.001
Disable or Modify Windows Event Log
GroupThreat Group-3390

Threat Group-3390 has used appcmd.exe to disable logging on a victim server.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.