ATT&CKReferencesPWC Cloud Hopper Technical Annex April 2017

PWC Cloud Hopper Technical Annex April 2017

PwC and BAE Systems. (2017, April). Operation Cloud Hopper: Technical Annex. Retrieved April 13, 2017.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software3

Campaigns0

None recorded.

Procedure examples44

TechniqueUsed byProcedure example
T1003.002
Security Account Manager
GroupmenuPass

menuPass has used a modified version of pentesting tools wmiexec.vbs and secretsdump.py to dump credentials.

T1003.004
LSA Secrets
GroupmenuPass

menuPass has used a modified version of pentesting tools wmiexec.vbs and secretsdump.py to dump credentials.

T1016
System Network Configuration Discovery
MalwareRedLeaves

RedLeaves can obtain information about network parameters.

T1016
System Network Configuration Discovery
GroupmenuPass

menuPass has used several tools to scan for open NetBIOS nameservers and enumerate NetBIOS sessions.

T1018
Remote System Discovery
GroupmenuPass

menuPass uses scripts to enumerate IP ranges on the victim network. menuPass has also issued the command net view /domain to a PlugX implant to gather information about remote systems on the network.

T1027.013
Encrypted/Encoded File
MalwareRedLeaves

A RedLeaves configuration file is encrypted with a simple XOR key, 0x53.

T1033
System Owner/User Discovery
MalwareRedLeaves

RedLeaves can obtain information about the logged on user both locally and for Remote Desktop sessions.

T1036.005
Match Legitimate Resource Name or Location
MalwareChChes

ChChes copies itself to an .exe file with a filename that is likely intended to imitate Norton Antivirus but has several letters reversed (e.g. notron.exe).

T1046
Network Service Discovery
GroupmenuPass

menuPass has used tcping.exe, similar to Ping, to probe port status on systems of interest.

T1047
Windows Management Instrumentation
GroupmenuPass

menuPass has used a modified version of pentesting script wmiexec.vbs, which logs into a remote machine using WMI.

T1049
System Network Connections Discovery
MalwareRedLeaves

RedLeaves can enumerate drives and Remote Desktop sessions.

T1053.005
Scheduled Task
GroupmenuPass

menuPass has used a script (atexec.py) to execute a command on a target machine via Task Scheduler.

T1056.001
Keylogging
MalwareEvilGrab

EvilGrab has the capability to capture keystrokes.

T1059.001
PowerShell
GroupmenuPass

menuPass uses PowerSploit to inject shellcode into PowerShell.

T1059.003
Windows Command Shell
GroupmenuPass

menuPass executes commands using a command-line interface and reverse shell. The group has used a modified version of pentesting script wmiexec.vbs to execute commands. menuPass has used malicious macros embedded inside Office documents to execute files.

T1059.003
Windows Command Shell
MalwareRedLeaves

RedLeaves can receive and execute commands with cmd.exe. It can also provide a reverse shell.

T1070.004
File Deletion
MalwareRedLeaves

RedLeaves can delete specified files.

T1082
System Information Discovery
MalwareRedLeaves

RedLeaves can gather extended system information including the hostname, OS version number, platform, memory information, time elapsed since system startup, and CPU information.

T1082
System Information Discovery
MalwareChChes

ChChes collects the victim hostname, window resolution, and Microsoft Windows version.

T1083
File and Directory Discovery
MalwareRedLeaves

RedLeaves can enumerate and search for files and directories.

T1087.002
Domain Account
GroupmenuPass

menuPass has used the Microsoft administration tool csvde.exe to export Active Directory data.

T1105
Ingress Tool Transfer
MalwareRedLeaves

RedLeaves is capable of downloading a file from a specified URL.

T1113
Screen Capture
MalwareEvilGrab

EvilGrab has the capability to capture screenshots.

T1123
Audio Capture
MalwareEvilGrab

EvilGrab has the capability to capture audio from a victim machine.

T1125
Video Capture
MalwareEvilGrab

EvilGrab has the capability to capture video from a victim machine.

T1199
Trusted Relationship
GroupmenuPass

menuPass has used legitimate access granted to Managed Service Providers in order to access victims of interest.

T1204.002
Malicious File
GroupmenuPass

menuPass has attempted to get victims to open malicious files such as Windows Shortcuts (.lnk) and/or Microsoft Office documents, sent via email as part of spearphishing campaigns.

T1218.004
InstallUtil
GroupmenuPass

menuPass has used InstallUtil.exe to execute malicious software.

T1543.003
Windows Service
MalwarePlugX

PlugX can be added as a service to establish persistence. PlugX also has a module to change service configurations as well as start, control, and delete services.

T1547.001
Registry Run Keys / Startup Folder
MalwareEvilGrab

EvilGrab adds a Registry Run key for ctfmon.exe to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwarePlugX

PlugX adds Run key entries in the Registry to establish persistence. PlugX has established persistence via the registry keys `HKCU\Software\Microsoft\Windows\CurrentVersion\Run` and `HKLM\Software\Microsoft\Windows\CurrentVersion\Run`.

T1547.001
Registry Run Keys / Startup Folder
MalwareRedLeaves

RedLeaves attempts to add a shortcut file in the Startup folder to achieve persistence. If this fails, it attempts to add Registry Run keys.

T1547.001
Registry Run Keys / Startup Folder
MalwareChChes

ChChes establishes persistence by adding a Registry Run key.

T1547.009
Shortcut Modification
MalwareRedLeaves

RedLeaves attempts to add a shortcut file in the Startup folder to achieve persistence.

T1553.002
Code Signing
MalwareChChes

ChChes samples were digitally signed with a certificate originally used by Hacking Team that was later leaked and subsequently revoked.

T1555.003
Credentials from Web Browsers
MalwareChChes

ChChes steals credentials stored inside Internet Explorer.

T1560.001
Archive via Utility
GroupmenuPass

menuPass has compressed files before exfiltration using TAR and RAR.

T1566.001
Spearphishing Attachment
GroupmenuPass

menuPass has sent malicious Office documents via email as part of spearphishing campaigns as well as executables disguised as documents.

T1571
Non-Standard Port
MalwareRedLeaves

RedLeaves can use HTTP over non-standard ports, such as 995, for C2.

T1573.001
Symmetric Cryptography
MalwareRedLeaves

RedLeaves has encrypted C2 traffic with RC4, previously using keys of 88888888 and babybear.

T1574.001
DLL
GroupmenuPass

menuPass has used DLL side-loading to launch versions of Mimikatz and PwDump6 as well as UPPERCUT. menuPass has also used DLL search order hijacking.

T1574.001
DLL
MalwarePlugX

PlugX has the ability to use DLL search order hijacking for installation on targeted systems. PlugX has also used DLL side-loading to evade anti-virus. PlugX has also used a legitimately signed executable to side-load a malicious payload within a DLL file.

T1588.002
Tool
GroupmenuPass

menuPass has used and modified open-source tools like Impacket, Mimikatz, and pwdump.

T1685
Disable or Modify Tools
MalwareChChes

ChChes can alter the victim's proxy configuration.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.