ATT&CKReferencesFireEye FIN7 Oct 2019

FireEye FIN7 Oct 2019

Carr, N, et all. (2019, October 10). Mahalo FIN7: Responding to the Criminal Operators’ New Tools and Techniques. Retrieved October 11, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software2

Campaigns0

None recorded.

Procedure examples9

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
MalwareBOOSTWRITE

BOOSTWRITE has encoded its payloads using a ChaCha stream cipher with a 256-bit key and 64-bit Initialization vector (IV) to evade detection.

T1056.004
Credential API Hooking
MalwareRDFSNIFFER

RDFSNIFFER hooks several Win32 API functions to hijack elements of the remote system management user-interface.

T1070.004
File Deletion
MalwareRDFSNIFFER

RDFSNIFFER has the capability of deleting local files.

T1106
Native API
MalwareRDFSNIFFER

RDFSNIFFER has used several Win32 API functions to interact with the victim machine.

T1129
Shared Modules
MalwareBOOSTWRITE

BOOSTWRITE has used the DWriteCreateFactory() function to load additional modules.

T1140
Deobfuscate/Decode Files or Information
MalwareBOOSTWRITE

BOOSTWRITE has used a a 32-byte long multi-XOR key to decode data inside its payload.

T1553.002
Code Signing
MalwareBOOSTWRITE

BOOSTWRITE has been signed by a valid CA.

T1574.001
DLL
MalwareBOOSTWRITE

BOOSTWRITE has exploited the loading of the legitimate Dwrite.dll file by actually loading the gdi library, which then loads the gdiplus library and ultimately loads the local Dwrite dll.

T1587.001
Malware
GroupFIN7

FIN7 has developed malware for use in operations, including the creation of infected removable media.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.