Sherstobitoff, R., Malhotra, A. (2018, April 24). Analyzing Operation GhostSecret: Attack Seeks to Steal Data Worldwide. Retrieved May 16, 2018.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareProxysvc | Proxysvc searches the local system and gathers data. |
| T1012 Query Registry |
MalwareProxysvc | Proxysvc gathers product names from the Registry key: |
| T1016 System Network Configuration Discovery |
MalwareProxysvc | Proxysvc collects the network adapter information and domain/username information based on current remote sessions. |
| T1041 Exfiltration Over C2 Channel |
MalwareProxysvc | Proxysvc performs data exfiltration over the control server channel using a custom protocol. |
| T1057 Process Discovery |
GroupLazarus Group | Several Lazarus Group malware families gather a list of running processes on a victim system and send it to their C2 server. A Destover-like variant used by Lazarus Group also gathers process times. |
| T1057 Process Discovery |
MalwareProxysvc | Proxysvc lists processes running on the system. |
| T1059.003 Windows Command Shell |
GroupLazarus Group | Lazarus Group malware uses cmd.exe to execute commands on a compromised host. A Destover-like variant used by Lazarus Group uses a batch file mechanism to delete its binaries from the system. |
| T1059.003 Windows Command Shell |
MalwareProxysvc | Proxysvc executes a binary on the system and logs the results into a temp file by using: |
| T1070.004 File Deletion |
MalwareProxysvc | Proxysvc can delete files indicated by the attacker and remove itself from disk using a batch file. |
| T1070.004 File Deletion |
GroupLazarus Group | Lazarus Group malware has deleted files in various ways, including "suicide scripts" to delete malware binaries from the victim. Lazarus Group also uses secure file deletion to delete files from the victim. |
| T1070.006 Timestomp |
GroupLazarus Group | Several Lazarus Group malware families use timestomping, including modifying the last write timestamp of a specified Registry key to a random date, as well as copying the timestamp for legitimate .exe files (such as calc.exe or mspaint.exe) to its dropped files. |
| T1071.001 Web Protocols |
MalwareProxysvc | Proxysvc uses HTTP over SSL to communicate commands with the control server. |
| T1082 System Information Discovery |
MalwareProxysvc | Proxysvc collects the OS version, country name, MAC address, computer name, and physical memory statistics. |
| T1082 System Information Discovery |
GroupLazarus Group | Several Lazarus Group malware families collect information on the type and version of the victim OS, as well as the victim computer name and CPU information. |
| T1083 File and Directory Discovery |
MalwareProxysvc | Proxysvc lists files in directories. |
| T1083 File and Directory Discovery |
GroupLazarus Group | Lazarus Group malware can use a common function to identify target files by their extension, and some also enumerate files and directories, including a Destover-like variant that lists files and gathers information for all drives. |
| T1119 Automated Collection |
MalwareProxysvc | Proxysvc automatically collects data about the victim and sends it to the control server. |
| T1124 System Time Discovery |
GroupLazarus Group | A Destover-like implant used by Lazarus Group can obtain the current system time and send it to the C2 server. |
| T1124 System Time Discovery |
MalwareProxysvc | As part of the data reconnaissance phase, Proxysvc grabs the system time to send back to the control server. |
| T1485 Data Destruction |
MalwareProxysvc | Proxysvc can overwrite files indicated by the attacker before deleting them. |
| T1569.002 Service Execution |
MalwareProxysvc | Proxysvc registers itself as a service on the victim’s machine to run as a standalone process. |
| T1573.001 Symmetric Cryptography |
GroupLazarus Group | Several Lazarus Group malware families encrypt C2 traffic using custom code that uses XOR with an ADD operation and XOR with a SUB operation. Another Lazarus Group malware sample XORs C2 traffic. Other Lazarus Group malware uses Caracachs encryption to encrypt C2 payloads. Lazarus Group has also used AES to encrypt C2 traffic. |
| T1680 Local Storage Discovery |
GroupLazarus Group | A Destover-like variant used by Lazarus Group collects disk space information and sends it to its C2 server. |
| T1680 Local Storage Discovery |
MalwareProxysvc | Proxysvc collects volume information for all drives on the system. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.