ATT&CKReferencesSecurelist LuckyMouse June 2018

Securelist LuckyMouse June 2018

Legezo, D. (2018, June 13). LuckyMouse hits national data center to organize country-level waterholing campaign. Retrieved August 18, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples8

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
GroupThreat Group-3390

A Threat Group-3390 tool can encrypt payloads using XOR. Threat Group-3390 malware is also obfuscated using Metasploit’s shikata_ga_nai encoder.

T1027.015
Compression
GroupThreat Group-3390

Threat Group-3390 malware is compressed with LZNT1 compression.

T1055.012
Process Hollowing
GroupThreat Group-3390

A Threat Group-3390 tool can spawn `svchost.exe` and inject the payload into that process.

T1056.001
Keylogging
GroupThreat Group-3390

Threat Group-3390 actors installed a credential logger on Microsoft Exchange servers. Threat Group-3390 also leveraged the reconnaissance framework, ScanBox, to capture keystrokes.

T1071.001
Web Protocols
GroupThreat Group-3390

Threat Group-3390 malware has used HTTP for C2.

T1140
Deobfuscate/Decode Files or Information
GroupThreat Group-3390

During execution, Threat Group-3390 malware deobfuscates and decompresses code that was encoded with Metasploit’s shikata_ga_nai encoder as well as compressed with LZNT1 compression.

T1189
Drive-by Compromise
GroupThreat Group-3390

Threat Group-3390 has extensively used strategic web compromises to target victims.

T1574.001
DLL
GroupThreat Group-3390

Threat Group-3390 has performed DLL search order hijacking to execute their payload. Threat Group-3390 has also used DLL side-loading, including by using legitimate Kaspersky antivirus variants as well as `rc.exe`, a legitimate Microsoft Resource Compiler.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.