Budaca, E., et al. (2021, August 25). FIN8 Threat Actor Goes Agile with New Sardonic Backdoor. Retrieved August 9, 2023.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1007 System Service Discovery |
MalwareSardonic | Sardonic has the ability to execute the `net start` command. |
| T1016 System Network Configuration Discovery |
MalwareSardonic | Sardonic has the ability to execute the `ipconfig` command. |
| T1016.001 Internet Connection Discovery |
GroupFIN8 | FIN8 has used the Ping command to check connectivity to actor-controlled C2 servers. |
| T1021.002 SMB/Windows Admin Shares |
GroupFIN8 | FIN8 has attempted to map to C$ on enumerated hosts to test the scope of their current credentials/context. FIN8 has also used smbexec from the Impacket suite for lateral movement. |
| T1027.010 Command Obfuscation |
MalwareSardonic | Sardonic PowerShell scripts can be encrypted with RC4 and compressed using Gzip. |
| T1047 Windows Management Instrumentation |
MalwareSardonic | Sardonic can use WMI to execute PowerShell commands on a compromised machine. |
| T1049 System Network Connections Discovery |
MalwareSardonic | Sardonic has the ability to execute the `netstat` command. |
| T1057 Process Discovery |
MalwareSardonic | Sardonic has the ability to execute the `tasklist` command. |
| T1059.001 PowerShell |
MalwareSardonic | Sardonic has the ability to execute PowerShell commands on a compromised machine. |
| T1070 Indicator Removal |
MalwareSardonic | Sardonic has the ability to delete created WMI objects to evade detections. |
| T1082 System Information Discovery |
MalwareSardonic | Sardonic has the ability to collect the computer name, and CPU manufacturer name from a compromised machine. Sardonic also has the ability to execute the `ver` and `systeminfo` commands. |
| T1095 Non-Application Layer Protocol |
MalwareSardonic | Sardonic can communicate with actor-controlled C2 servers by using a custom little-endian binary protocol. |
| T1105 Ingress Tool Transfer |
MalwareSardonic | Sardonic has the ability to upload additional malicious files to a compromised machine. |
| T1106 Native API |
MalwareSardonic | Sardonic has the ability to call Win32 API functions to determine if `powershell.exe` is running. |
| T1132.001 Standard Encoding |
MalwareSardonic | Sardonic can encode client ID data in 32 uppercase hex characters and transfer to the actor-controlled C2 server. |
| T1135 Network Share Discovery |
MalwareSardonic | Sardonic has the ability to execute the `net view` command. |
| T1546.003 Windows Management Instrumentation Event Subscription |
MalwareSardonic | Sardonic can use a WMI event filter to invoke a command-line event consumer to gain persistence. |
| T1571 Non-Standard Port |
MalwareSardonic | Sardonic has the ability to connect with actor-controlled C2 servers using a custom binary protocol over port 443. |
| T1573.001 Symmetric Cryptography |
MalwareSardonic | Sardonic has the ability to use an RC4 key to encrypt communications to and from actor-controlled C2 servers. |
| T1573.002 Asymmetric Cryptography |
MalwareSardonic | Sardonic has the ability to send a random 64-byte RC4 key to communicate with actor-controlled C2 servers by using an RSA public key. |
| T1588.002 Tool |
GroupFIN8 | FIN8 has used open-source tools such as Impacket for targeting efforts. |
| T1588.003 Code Signing Certificates |
GroupFIN8 | FIN8 has used an expired open-source X.509 certificate for testing in the OpenSSL repository, to connect to actor-controlled C2 servers. |
| T1620 Reflective Code Loading |
MalwareSardonic | Sardonic has a plugin system that can load specially made DLLs into memory and execute their functions. |
| T1680 Local Storage Discovery |
MalwareSardonic | Sardonic has the ability to collect the C:\ drive serial number from a compromised machine. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.