Beek, C. (2020, November 5). Operation North Star: Behind The Scenes. Retrieved December 20, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareTorisma | Torisma can collect the local MAC address using `GetAdaptersInfo` as well as the system's IP address. |
| T1027.002 Software Packing |
MalwareTorisma | Torisma has been packed with Iz4 compression. |
| T1027.002 Software Packing |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group packed malicious .db files with Themida to evade detection. |
| T1027.013 Encrypted/Encoded File |
MalwareTorisma | Torisma has been Base64 encoded and AES encrypted. |
| T1027.013 Encrypted/Encoded File |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group encrypted malware such as DRATzarus with XOR and DLL files with base64. |
| T1041 Exfiltration Over C2 Channel |
MalwareTorisma | Torisma can send victim data to an actor-controlled C2 server. |
| T1049 System Network Connections Discovery |
MalwareTorisma | Torisma can use `WTSEnumerateSessionsW` to monitor remote desktop connections. |
| T1071.001 Web Protocols |
MalwareTorisma | Torisma can use HTTP and HTTPS for C2 communications. |
| T1106 Native API |
MalwareTorisma | Torisma has used various Windows API calls. |
| T1124 System Time Discovery |
MalwareTorisma | Torisma can collect the current time on a victim machine. |
| T1132.001 Standard Encoding |
MalwareTorisma | Torisma has encoded C2 communications with Base64. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareTorisma | Torisma has used XOR and Base64 to decode C2 data. |
| T1480 Execution Guardrails |
MalwareTorisma | Torisma is only delivered to a compromised host if the victim's IP address is on an allow-list. |
| T1573.001 Symmetric Cryptography |
MalwareTorisma | Torisma has encrypted its C2 communications using XOR and VEST-32. |
| T1584.001 Domains |
CampaignOperation Dream Job | For Operation Dream Job, Lazarus Group compromised domains in Italy and other countries for their C2 infrastructure. |
| T1587.001 Malware |
CampaignOperation Dream Job | For Operation Dream Job, Lazarus Group developed custom tools such as Sumarta, DBLL Dropper, Torisma, and DRATzarus for their operations. |
| T1608.001 Upload Malware |
CampaignOperation Dream Job | For Operation Dream Job, Lazarus Group used compromised servers to host malware. |
| T1680 Local Storage Discovery |
MalwareTorisma | Torisma can use `GetlogicalDrives` to get a bitmask of all drives available on a compromised system. It can also use `GetDriveType` to determine if a new drive is a CD-ROM drive. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.