Symantec Threat Hunter Team. (2023, July 18). FIN8 Uses Revamped Sardonic Backdoor to Deliver Noberus Ransomware. Retrieved August 9, 2023.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareSardonic | Sardonic has the ability to collect data from a compromised machine to deliver to the attacker. |
| T1027 Obfuscated Files or Information |
MalwareSardonic | Sardonic can use certain ConfuserEx features for obfuscation and can be encoded in a base64 string. |
| T1033 System Owner/User Discovery |
GroupFIN8 | FIN8 has executed the command `quser` to display the session details of a compromised machine. |
| T1047 Windows Management Instrumentation |
GroupFIN8 | FIN8's malicious spearphishing payloads use WMI to launch malware and spawn `cmd.exe` execution. FIN8 has also used WMIC and the Impacket suite for lateral movement, as well as during and post compromise cleanup activities. |
| T1055.004 Asynchronous Procedure Call |
MalwareSardonic | Sardonic can use the `QueueUserAPC` API to execute shellcode on a compromised machine. |
| T1059.001 PowerShell |
GroupFIN8 | FIN8's malicious spearphishing payloads are executed as PowerShell. FIN8 has also used PowerShell for lateral movement and credential access. |
| T1059.003 Windows Command Shell |
GroupFIN8 | FIN8 has used a Batch file to automate frequently executed post compromise cleanup activities. FIN8 has also executed commands remotely via `cmd.exe`. |
| T1059.003 Windows Command Shell |
MalwareSardonic | Sardonic has the ability to run `cmd.exe` or other interactive processes on a compromised computer. |
| T1070.004 File Deletion |
GroupFIN8 | FIN8 has deleted tmp and prefetch files during post compromise cleanup activities. FIN8 has also deleted PowerShell scripts to evade detection on compromised machines. |
| T1082 System Information Discovery |
GroupFIN8 | FIN8 has used PowerShell Scripts to check the architecture of a compromised machine before the selection of a 32-bit or 64-bit version of a malicious .NET loader. |
| T1134.001 Token Impersonation/Theft |
GroupFIN8 | FIN8 has used a malicious framework designed to impersonate the lsass.exe/vmtoolsd.exe token. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareSardonic | Sardonic can first decrypt with the RC4 algorithm using a hardcoded decryption key before decompressing. |
| T1486 Data Encrypted for Impact |
GroupFIN8 | FIN8 has deployed ransomware such as Ragnar Locker, White Rabbit, and attempted to execute Noberus on compromised networks. |
| T1620 Reflective Code Loading |
MalwareSardonic | Sardonic has a plugin system that can load specially made DLLs into memory and execute their functions. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.