ATT&CKReferencesSymantec FIN8 Jul 2023

Symantec FIN8 Jul 2023

Symantec Threat Hunter Team. (2023, July 18). FIN8 Uses Revamped Sardonic Backdoor to Deliver Noberus Ransomware. Retrieved August 9, 2023.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples14

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareSardonic

Sardonic has the ability to collect data from a compromised machine to deliver to the attacker.

T1027
Obfuscated Files or Information
MalwareSardonic

Sardonic can use certain ConfuserEx features for obfuscation and can be encoded in a base64 string.

T1033
System Owner/User Discovery
GroupFIN8

FIN8 has executed the command `quser` to display the session details of a compromised machine.

T1047
Windows Management Instrumentation
GroupFIN8

FIN8's malicious spearphishing payloads use WMI to launch malware and spawn `cmd.exe` execution. FIN8 has also used WMIC and the Impacket suite for lateral movement, as well as during and post compromise cleanup activities.

T1055.004
Asynchronous Procedure Call
MalwareSardonic

Sardonic can use the `QueueUserAPC` API to execute shellcode on a compromised machine.

T1059.001
PowerShell
GroupFIN8

FIN8's malicious spearphishing payloads are executed as PowerShell. FIN8 has also used PowerShell for lateral movement and credential access.

T1059.003
Windows Command Shell
GroupFIN8

FIN8 has used a Batch file to automate frequently executed post compromise cleanup activities. FIN8 has also executed commands remotely via `cmd.exe`.

T1059.003
Windows Command Shell
MalwareSardonic

Sardonic has the ability to run `cmd.exe` or other interactive processes on a compromised computer.

T1070.004
File Deletion
GroupFIN8

FIN8 has deleted tmp and prefetch files during post compromise cleanup activities. FIN8 has also deleted PowerShell scripts to evade detection on compromised machines.

T1082
System Information Discovery
GroupFIN8

FIN8 has used PowerShell Scripts to check the architecture of a compromised machine before the selection of a 32-bit or 64-bit version of a malicious .NET loader.

T1134.001
Token Impersonation/Theft
GroupFIN8

FIN8 has used a malicious framework designed to impersonate the lsass.exe/vmtoolsd.exe token.

T1140
Deobfuscate/Decode Files or Information
MalwareSardonic

Sardonic can first decrypt with the RC4 algorithm using a hardcoded decryption key before decompressing.

T1486
Data Encrypted for Impact
GroupFIN8

FIN8 has deployed ransomware such as Ragnar Locker, White Rabbit, and attempted to execute Noberus on compromised networks.

T1620
Reflective Code Loading
MalwareSardonic

Sardonic has a plugin system that can load specially made DLLs into memory and execute their functions.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.