Counter Threat Unit Research Team. (2017, June 27). BRONZE UNION Cyberespionage Persists Despite Disclosures. Retrieved July 13, 2017.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupThreat Group-3390 | Threat Group-3390 actors have used a modified version of Mimikatz called Wrapikatz to dump credentials. They have also dumped credentials from domain controllers. |
| T1003.002 Security Account Manager |
GroupThreat Group-3390 | Threat Group-3390 actors have used gsecdump to dump credentials. They have also dumped credentials from domain controllers. |
| T1003.004 LSA Secrets |
GroupThreat Group-3390 | Threat Group-3390 actors have used gsecdump to dump credentials. They have also dumped credentials from domain controllers. |
| T1005 Data from Local System |
GroupThreat Group-3390 | Threat Group-3390 ran a command to compile an archive of file types of interest from the victim user's directories. |
| T1021.006 Windows Remote Management |
GroupThreat Group-3390 | Threat Group-3390 has used WinRM to enable remote execution. |
| T1049 System Network Connections Discovery |
GroupThreat Group-3390 | Threat Group-3390 has used `net use` and `netstat` to conduct internal discovery of systems. The group has also used `quser.exe` to identify existing RDP sessions on a victim. |
| T1059.001 PowerShell |
GroupThreat Group-3390 | Threat Group-3390 has used PowerShell for execution. |
| T1059.003 Windows Command Shell |
GroupThreat Group-3390 | Threat Group-3390 has used command-line interfaces for execution. |
| T1059.003 Windows Command Shell |
MalwareChina Chopper | China Chopper's server component is capable of opening a command terminal. |
| T1068 Exploitation for Privilege Escalation |
GroupThreat Group-3390 | Threat Group-3390 has used CVE-2014-6324 and CVE-2017-0213 to escalate privileges. |
| T1070.004 File Deletion |
GroupThreat Group-3390 | Threat Group-3390 has deleted existing logs and exfiltrated file archives from a victim. |
| T1070.005 Network Share Connection Removal |
GroupThreat Group-3390 | Threat Group-3390 has detached network shares after exfiltrating files, likely to evade detection. |
| T1074.001 Local Data Staging |
GroupThreat Group-3390 | Threat Group-3390 has locally staged encrypted archives for later exfiltration efforts. |
| T1074.002 Remote Data Staging |
GroupThreat Group-3390 | Threat Group-3390 has moved staged encrypted archives to Internet-facing servers that had previously been compromised with China Chopper prior to exfiltration. |
| T1087.001 Local Account |
GroupThreat Group-3390 | Threat Group-3390 has used |
| T1119 Automated Collection |
GroupThreat Group-3390 | Threat Group-3390 ran a command to compile an archive of file types of interest from the victim user's directories. |
| T1133 External Remote Services |
GroupThreat Group-3390 | Threat Group-3390 actors look for and use VPN profiles during an operation to access the network using external VPN services. Threat Group-3390 has also obtained OWA account credentials during intrusions that it subsequently used to attempt to regain access when evicted from a victim network. |
| T1560.002 Archive via Library |
GroupThreat Group-3390 | Threat Group-3390 has used RAR to compress, encrypt, and password-protect files prior to exfiltration. |
| T1574.001 DLL |
GroupThreat Group-3390 | Threat Group-3390 has performed DLL search order hijacking to execute their payload. Threat Group-3390 has also used DLL side-loading, including by using legitimate Kaspersky antivirus variants as well as `rc.exe`, a legitimate Microsoft Resource Compiler. |
| T1685.001 Disable or Modify Windows Event Log |
GroupThreat Group-3390 | Threat Group-3390 has used appcmd.exe to disable logging on a victim server. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.