ATT&CKReferencesMcAfee Lazarus Nov 2020

McAfee Lazarus Nov 2020

Beek, C. (2020, November 5). Operation North Star: Behind The Scenes. Retrieved December 20, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples18

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareTorisma

Torisma can collect the local MAC address using `GetAdaptersInfo` as well as the system's IP address.

T1027.002
Software Packing
MalwareTorisma

Torisma has been packed with Iz4 compression.

T1027.002
Software Packing
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group packed malicious .db files with Themida to evade detection.

T1027.013
Encrypted/Encoded File
MalwareTorisma

Torisma has been Base64 encoded and AES encrypted.

T1027.013
Encrypted/Encoded File
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group encrypted malware such as DRATzarus with XOR and DLL files with base64.

T1041
Exfiltration Over C2 Channel
MalwareTorisma

Torisma can send victim data to an actor-controlled C2 server.

T1049
System Network Connections Discovery
MalwareTorisma

Torisma can use `WTSEnumerateSessionsW` to monitor remote desktop connections.

T1071.001
Web Protocols
MalwareTorisma

Torisma can use HTTP and HTTPS for C2 communications.

T1106
Native API
MalwareTorisma

Torisma has used various Windows API calls.

T1124
System Time Discovery
MalwareTorisma

Torisma can collect the current time on a victim machine.

T1132.001
Standard Encoding
MalwareTorisma

Torisma has encoded C2 communications with Base64.

T1140
Deobfuscate/Decode Files or Information
MalwareTorisma

Torisma has used XOR and Base64 to decode C2 data.

T1480
Execution Guardrails
MalwareTorisma

Torisma is only delivered to a compromised host if the victim's IP address is on an allow-list.

T1573.001
Symmetric Cryptography
MalwareTorisma

Torisma has encrypted its C2 communications using XOR and VEST-32.

T1584.001
Domains
CampaignOperation Dream Job

For Operation Dream Job, Lazarus Group compromised domains in Italy and other countries for their C2 infrastructure.

T1587.001
Malware
CampaignOperation Dream Job

For Operation Dream Job, Lazarus Group developed custom tools such as Sumarta, DBLL Dropper, Torisma, and DRATzarus for their operations.

T1608.001
Upload Malware
CampaignOperation Dream Job

For Operation Dream Job, Lazarus Group used compromised servers to host malware.

T1680
Local Storage Discovery
MalwareTorisma

Torisma can use `GetlogicalDrives` to get a bitmask of all drives available on a compromised system. It can also use `GetDriveType` to determine if a new drive is a CD-ROM drive.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.