ATT&CKReferencesUnit 42 C0d0so0 Jan 2016

Unit 42 C0d0so0 Jan 2016

Grunzweig, J., Lee, B. (2016, January 22). New Attacks Linked to C0d0so0 Group. Retrieved August 2, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples11

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
GroupAPT19

APT19 used an HTTP malware variant and a Port 22 malware variant to collect the MAC address and IP address from the victim’s machine.

T1033
System Owner/User Discovery
GroupAPT19

APT19 used an HTTP malware variant and a Port 22 malware variant to collect the victim’s username.

T1071.001
Web Protocols
GroupAPT19

APT19 used HTTP for C2 communications. APT19 also used an HTTP malware variant to communicate over HTTP for C2.

T1082
System Information Discovery
GroupAPT19

APT19 collected system architecture information. APT19 used an HTTP malware variant and a Port 22 malware variant to gather the hostname and CPU information from the victim’s machine.

T1112
Modify Registry
GroupAPT19

APT19 uses a Port 22 malware variant to modify several Registry keys.

T1132.001
Standard Encoding
GroupAPT19

An APT19 HTTP malware variant used Base64 to encode communications to the C2 server.

T1140
Deobfuscate/Decode Files or Information
GroupAPT19

An APT19 HTTP malware variant decrypts strings using single-byte XOR keys.

T1189
Drive-by Compromise
GroupAPT19

APT19 performed a watering hole attack on forbes.com in 2014 to compromise targets.

T1543.003
Windows Service
GroupAPT19

An APT19 Port 22 malware variant registers itself as a service.

T1547.001
Registry Run Keys / Startup Folder
GroupAPT19

An APT19 HTTP malware variant establishes persistence by setting the Registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Windows Debug Tools-%LOCALAPPDATA%\.

T1574.001
DLL
GroupAPT19

APT19 launched an HTTP malware variant and a Port 22 malware variant using a legitimate executable that loaded the malicious DLL.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.