ATT&CKReferencesNicolas Falliere, Liam O Murchu, Eric Chien February 2011

Nicolas Falliere, Liam O Murchu, Eric Chien February 2011

Nicolas Falliere, Liam O Murchu, Eric Chien 2011, February W32.Stuxnet Dossier (Version 1.4) Retrieved November 17, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples44

TechniqueUsed byProcedure example
T1008
Fallback Channels
MalwareStuxnet

Stuxnet has the ability to generate new C2 domains.

T1012
Query Registry
MalwareStuxnet

Stuxnet searches the Registry for indicators of security programs.

T1014
Rootkit
MalwareStuxnet

Stuxnet uses a Windows rootkit to mask its binaries and other relevant files.

T1016
System Network Configuration Discovery
MalwareStuxnet

Stuxnet collects the IP address of a compromised system.

T1021
Remote Services
MalwareStuxnet

Stuxnet can propagate via peer-to-peer communication and updates using RPC.

T1021.002
SMB/Windows Admin Shares
MalwareStuxnet

Stuxnet propagates to available network shares.

T1027.013
Encrypted/Encoded File
MalwareStuxnet

Stuxnet uses encrypted configuration blocks and writes encrypted files to disk.

T1041
Exfiltration Over C2 Channel
MalwareStuxnet

Stuxnet sends compromised victim information via HTTP.

T1047
Windows Management Instrumentation
MalwareStuxnet

Stuxnet used WMI with an explorer.exe token to execute on a remote share.

T1053.005
Scheduled Task
MalwareStuxnet

Stuxnet schedules a network job to execute two minutes after host infection.

T1055.001
Dynamic-link Library Injection
MalwareStuxnet

Stuxnet injects an entire DLL into an existing, newly created, or preselected trusted process.

T1068
Exploitation for Privilege Escalation
MalwareStuxnet

Stuxnet used MS10-073 and an undisclosed Task Scheduler vulnerability to escalate privileges on local Windows machines.

T1070
Indicator Removal
MalwareStuxnet

Stuxnet can delete OLE Automation and SQL stored procedures used to store malicious payloads.

T1070.004
File Deletion
MalwareStuxnet

Stuxnet uses an RPC server that contains a routine for file deletion and also removes itself from the system through a DLL export by deleting specific files.

T1070.006
Timestomp
MalwareStuxnet

Stuxnet extracts and writes driver files that match the times of other legitimate files.

T1071.001
Web Protocols
MalwareStuxnet

Stuxnet uses HTTP to communicate with a command and control server.

T1078.001
Default Accounts
MalwareStuxnet

Stuxnet infected WinCC machines via a hardcoded database server password.

T1078.002
Domain Accounts
MalwareStuxnet

Stuxnet attempts to access network resources with a domain account’s credentials.

T1080
Taint Shared Content
MalwareStuxnet

Stuxnet infects remote servers via network shares and by infecting WinCC database views with malicious code.

T1082
System Information Discovery
MalwareStuxnet

Stuxnet collects system information including computer and domain names, OS version, and S7P paths.

T1083
File and Directory Discovery
MalwareStuxnet

Stuxnet uses a driver to scan for specific filesystem driver objects.

T1087.001
Local Account
MalwareStuxnet

Stuxnet enumerates user accounts of the local host.

T1087.002
Domain Account
MalwareStuxnet

Stuxnet enumerates user accounts of the domain.

T1090.001
Internal Proxy
MalwareStuxnet

Stuxnet installs an RPC server for P2P communications.

T1091
Replication Through Removable Media
MalwareStuxnet

Stuxnet can propagate via removable media using an autorun.inf file or the CVE-2010-2568 LNK vulnerability.

T1106
Native API
MalwareStuxnet

Stuxnet uses the SetSecurityDescriptorDacl API to reduce object integrity levels.

T1112
Modify Registry
MalwareStuxnet

Stuxnet can create registry keys to load driver files.

T1120
Peripheral Device Discovery
MalwareStuxnet

Stuxnet enumerates removable drives for infection.

T1124
System Time Discovery
MalwareStuxnet

Stuxnet collects the time and date of a system when it is infected.

T1129
Shared Modules
MalwareStuxnet

Stuxnet calls LoadLibrary then executes exports from a DLL.

T1132.001
Standard Encoding
MalwareStuxnet

Stuxnet transforms encrypted binary data into an ASCII string in order to use it as a URL parameter value.

T1134.001
Token Impersonation/Theft
MalwareStuxnet

Stuxnet attempts to impersonate an anonymous token to enumerate bindings in the service control manager.

T1135
Network Share Discovery
MalwareStuxnet

Stuxnet enumerates the directories of a network resource.

T1140
Deobfuscate/Decode Files or Information
MalwareStuxnet

Stuxnet decrypts resources that are loaded into memory and executed.

T1210
Exploitation of Remote Services
MalwareStuxnet

Stuxnet propagates using the MS10-061 Print Spooler and MS08-067 Windows Server Service vulnerabilities.

T1480
Execution Guardrails
MalwareStuxnet

Stuxnet checks for specific operating systems on 32-bit machines, Registry keys, and dates for vulnerabilities, and will exit execution if the values are not met.

T1505.001
SQL Stored Procedures
MalwareStuxnet

Stuxnet used xp_cmdshell to store and execute SQL code.

T1518.001
Security Software Discovery
MalwareStuxnet

Stuxnet enumerates the currently running processes related to a variety of security products.

T1543.003
Windows Service
MalwareStuxnet

Stuxnet uses a driver registered as a boot start service as the main load-point.

T1553.002
Code Signing
MalwareStuxnet

Stuxnet used a digitally signed driver with a compromised Realtek certificate.

T1560.003
Archive via Custom Method
MalwareStuxnet

Stuxnet encrypts exfiltrated data via C2 with static 31-byte long XOR keys.

T1570
Lateral Tool Transfer
MalwareStuxnet

Stuxnet uses an RPC server that contains a file dropping routine and support for payload version updates for P2P communications within a victim network.

T1573.001
Symmetric Cryptography
MalwareStuxnet

Stuxnet encodes the payload of system information sent to the command and control servers using a one byte 0xFF XOR key. Stuxnet also uses a 31-byte long static byte string to XOR data sent to command and control servers. The servers use a different static key to encrypt replies to the implant.

T1685
Disable or Modify Tools
MalwareStuxnet

Stuxnet reduces the integrity level of objects to allow write actions.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.