ATT&CKReferencesSecurelist Octopus Oct 2018

Securelist Octopus Oct 2018

Kaspersky Lab's Global Research & Analysis Team. (2018, October 15). Octopus-infested seas of Central Asia. Retrieved November 14, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples16

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareOctopus

Octopus can collect the host IP address from the victim’s machine.

T1033
System Owner/User Discovery
MalwareOctopus

Octopus can collect the username from the victim’s machine.

T1036
Masquerading
GroupNomadic Octopus

Nomadic Octopus attempted to make Octopus appear as a Telegram Messenger with a Russian interface.

T1036.005
Match Legitimate Resource Name or Location
MalwareOctopus

Octopus has been disguised as legitimate programs, such as Java and Telegram Messenger.

T1041
Exfiltration Over C2 Channel
MalwareOctopus

Octopus has uploaded stolen files and data from a victim's machine over its C2 channel.

T1047
Windows Management Instrumentation
MalwareOctopus

Octopus has used wmic.exe for local discovery information.

T1071.001
Web Protocols
MalwareOctopus

Octopus has used HTTP GET and POST requests for C2 communications.

T1074.001
Local Data Staging
MalwareOctopus

Octopus has stored collected information in the Application Data directory on a compromised host.

T1082
System Information Discovery
MalwareOctopus

Octopus can collect the computer name, OS version, and OS architecture information.

T1083
File and Directory Discovery
MalwareOctopus

Octopus can collect information on the Windows directory and searches for compressed RAR files on the host.

T1105
Ingress Tool Transfer
MalwareOctopus

Octopus can download additional files and tools onto the victim’s machine.

T1113
Screen Capture
MalwareOctopus

Octopus can capture screenshots of the victims’ machine.

T1132.001
Standard Encoding
MalwareOctopus

Octopus has encoded C2 communications in Base64.

T1204.002
Malicious File
GroupNomadic Octopus

Nomadic Octopus as attempted to lure victims into clicking on malicious attachments within spearphishing emails.

T1547.001
Registry Run Keys / Startup Folder
MalwareOctopus

Octopus achieved persistence by placing a malicious executable in the startup directory and has added the HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run key to the Registry.

T1680
Local Storage Discovery
MalwareOctopus

Octopus can collect system drive and disk size information.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.