ATT&CKReferencesBitdefender Sardonic Aug 2021

Bitdefender Sardonic Aug 2021

Budaca, E., et al. (2021, August 25). FIN8 Threat Actor Goes Agile with New Sardonic Backdoor. Retrieved August 9, 2023.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples24

TechniqueUsed byProcedure example
T1007
System Service Discovery
MalwareSardonic

Sardonic has the ability to execute the `net start` command.

T1016
System Network Configuration Discovery
MalwareSardonic

Sardonic has the ability to execute the `ipconfig` command.

T1016.001
Internet Connection Discovery
GroupFIN8

FIN8 has used the Ping command to check connectivity to actor-controlled C2 servers.

T1021.002
SMB/Windows Admin Shares
GroupFIN8

FIN8 has attempted to map to C$ on enumerated hosts to test the scope of their current credentials/context. FIN8 has also used smbexec from the Impacket suite for lateral movement.

T1027.010
Command Obfuscation
MalwareSardonic

Sardonic PowerShell scripts can be encrypted with RC4 and compressed using Gzip.

T1047
Windows Management Instrumentation
MalwareSardonic

Sardonic can use WMI to execute PowerShell commands on a compromised machine.

T1049
System Network Connections Discovery
MalwareSardonic

Sardonic has the ability to execute the `netstat` command.

T1057
Process Discovery
MalwareSardonic

Sardonic has the ability to execute the `tasklist` command.

T1059.001
PowerShell
MalwareSardonic

Sardonic has the ability to execute PowerShell commands on a compromised machine.

T1070
Indicator Removal
MalwareSardonic

Sardonic has the ability to delete created WMI objects to evade detections.

T1082
System Information Discovery
MalwareSardonic

Sardonic has the ability to collect the computer name, and CPU manufacturer name from a compromised machine. Sardonic also has the ability to execute the `ver` and `systeminfo` commands.

T1095
Non-Application Layer Protocol
MalwareSardonic

Sardonic can communicate with actor-controlled C2 servers by using a custom little-endian binary protocol.

T1105
Ingress Tool Transfer
MalwareSardonic

Sardonic has the ability to upload additional malicious files to a compromised machine.

T1106
Native API
MalwareSardonic

Sardonic has the ability to call Win32 API functions to determine if `powershell.exe` is running.

T1132.001
Standard Encoding
MalwareSardonic

Sardonic can encode client ID data in 32 uppercase hex characters and transfer to the actor-controlled C2 server.

T1135
Network Share Discovery
MalwareSardonic

Sardonic has the ability to execute the `net view` command.

T1546.003
Windows Management Instrumentation Event Subscription
MalwareSardonic

Sardonic can use a WMI event filter to invoke a command-line event consumer to gain persistence.

T1571
Non-Standard Port
MalwareSardonic

Sardonic has the ability to connect with actor-controlled C2 servers using a custom binary protocol over port 443.

T1573.001
Symmetric Cryptography
MalwareSardonic

Sardonic has the ability to use an RC4 key to encrypt communications to and from actor-controlled C2 servers.

T1573.002
Asymmetric Cryptography
MalwareSardonic

Sardonic has the ability to send a random 64-byte RC4 key to communicate with actor-controlled C2 servers by using an RSA public key.

T1588.002
Tool
GroupFIN8

FIN8 has used open-source tools such as Impacket for targeting efforts.

T1588.003
Code Signing Certificates
GroupFIN8

FIN8 has used an expired open-source X.509 certificate for testing in the OpenSSL repository, to connect to actor-controlled C2 servers.

T1620
Reflective Code Loading
MalwareSardonic

Sardonic has a plugin system that can load specially made DLLs into memory and execute their functions.

T1680
Local Storage Discovery
MalwareSardonic

Sardonic has the ability to collect the C:\ drive serial number from a compromised machine.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.