ATT&CKReferencesLotus Blossom Dec 2015

Lotus Blossom Dec 2015

Falcone, R. and Miller-Osborn, J.. (2015, December 18). Attack on French Diplomat Linked to Operation Lotus Blossom. Retrieved February 15, 2016.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples6

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
MalwareEmissary

Variants of Emissary encrypt payloads using various XOR ciphers, as well as a custom algorithm that uses the "srand" and "rand" functions.

T1055.001
Dynamic-link Library Injection
MalwareEmissary

Emissary injects its DLL file into a newly spawned Internet Explorer process.

T1059.003
Windows Command Shell
MalwareEmissary

Emissary has the capability to create a remote shell and execute specified commands.

T1071.001
Web Protocols
MalwareEmissary

Emissary uses HTTP or HTTPS for C2.

T1105
Ingress Tool Transfer
MalwareEmissary

Emissary has the capability to download files from the C2 server.

T1573.001
Symmetric Cryptography
MalwareEmissary

The C2 server response to a beacon sent by a variant of Emissary contains a 36-character GUID value that is used as an encryption key for subsequent network communications. Some variants of Emissary use various XOR operations to encrypt C2 data.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.