ATT&CKReferencesMcAfee GhostSecret

McAfee GhostSecret

Sherstobitoff, R., Malhotra, A. (2018, April 24). Analyzing Operation GhostSecret: Attack Seeks to Steal Data Worldwide. Retrieved May 16, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples24

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareProxysvc

Proxysvc searches the local system and gathers data.

T1012
Query Registry
MalwareProxysvc

Proxysvc gathers product names from the Registry key: HKLM\Software\Microsoft\Windows NT\CurrentVersion ProductName and the processor description from the Registry key HKLM\HARDWARE\DESCRIPTION\System\CentralProcessor\0 ProcessorNameString.

T1016
System Network Configuration Discovery
MalwareProxysvc

Proxysvc collects the network adapter information and domain/username information based on current remote sessions.

T1041
Exfiltration Over C2 Channel
MalwareProxysvc

Proxysvc performs data exfiltration over the control server channel using a custom protocol.

T1057
Process Discovery
GroupLazarus Group

Several Lazarus Group malware families gather a list of running processes on a victim system and send it to their C2 server. A Destover-like variant used by Lazarus Group also gathers process times.

T1057
Process Discovery
MalwareProxysvc

Proxysvc lists processes running on the system.

T1059.003
Windows Command Shell
GroupLazarus Group

Lazarus Group malware uses cmd.exe to execute commands on a compromised host. A Destover-like variant used by Lazarus Group uses a batch file mechanism to delete its binaries from the system.

T1059.003
Windows Command Shell
MalwareProxysvc

Proxysvc executes a binary on the system and logs the results into a temp file by using: cmd.exe /c "<file_path> > %temp%\PM* .tmp 2>&1".

T1070.004
File Deletion
MalwareProxysvc

Proxysvc can delete files indicated by the attacker and remove itself from disk using a batch file.

T1070.004
File Deletion
GroupLazarus Group

Lazarus Group malware has deleted files in various ways, including "suicide scripts" to delete malware binaries from the victim. Lazarus Group also uses secure file deletion to delete files from the victim.

T1070.006
Timestomp
GroupLazarus Group

Several Lazarus Group malware families use timestomping, including modifying the last write timestamp of a specified Registry key to a random date, as well as copying the timestamp for legitimate .exe files (such as calc.exe or mspaint.exe) to its dropped files.

T1071.001
Web Protocols
MalwareProxysvc

Proxysvc uses HTTP over SSL to communicate commands with the control server.

T1082
System Information Discovery
MalwareProxysvc

Proxysvc collects the OS version, country name, MAC address, computer name, and physical memory statistics.

T1082
System Information Discovery
GroupLazarus Group

Several Lazarus Group malware families collect information on the type and version of the victim OS, as well as the victim computer name and CPU information.

T1083
File and Directory Discovery
MalwareProxysvc

Proxysvc lists files in directories.

T1083
File and Directory Discovery
GroupLazarus Group

Lazarus Group malware can use a common function to identify target files by their extension, and some also enumerate files and directories, including a Destover-like variant that lists files and gathers information for all drives.

T1119
Automated Collection
MalwareProxysvc

Proxysvc automatically collects data about the victim and sends it to the control server.

T1124
System Time Discovery
GroupLazarus Group

A Destover-like implant used by Lazarus Group can obtain the current system time and send it to the C2 server.

T1124
System Time Discovery
MalwareProxysvc

As part of the data reconnaissance phase, Proxysvc grabs the system time to send back to the control server.

T1485
Data Destruction
MalwareProxysvc

Proxysvc can overwrite files indicated by the attacker before deleting them.

T1569.002
Service Execution
MalwareProxysvc

Proxysvc registers itself as a service on the victim’s machine to run as a standalone process.

T1573.001
Symmetric Cryptography
GroupLazarus Group

Several Lazarus Group malware families encrypt C2 traffic using custom code that uses XOR with an ADD operation and XOR with a SUB operation. Another Lazarus Group malware sample XORs C2 traffic. Other Lazarus Group malware uses Caracachs encryption to encrypt C2 payloads. Lazarus Group has also used AES to encrypt C2 traffic.

T1680
Local Storage Discovery
GroupLazarus Group

A Destover-like variant used by Lazarus Group collects disk space information and sends it to its C2 server.

T1680
Local Storage Discovery
MalwareProxysvc

Proxysvc collects volume information for all drives on the system.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.