PwC and BAE Systems. (2017, April). Operation Cloud Hopper: Technical Annex. Retrieved April 13, 2017.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.002 Security Account Manager |
GroupmenuPass | menuPass has used a modified version of pentesting tools wmiexec.vbs and secretsdump.py to dump credentials. |
| T1003.004 LSA Secrets |
GroupmenuPass | menuPass has used a modified version of pentesting tools wmiexec.vbs and secretsdump.py to dump credentials. |
| T1016 System Network Configuration Discovery |
MalwareRedLeaves | RedLeaves can obtain information about network parameters. |
| T1016 System Network Configuration Discovery |
GroupmenuPass | menuPass has used several tools to scan for open NetBIOS nameservers and enumerate NetBIOS sessions. |
| T1018 Remote System Discovery |
GroupmenuPass | menuPass uses scripts to enumerate IP ranges on the victim network. menuPass has also issued the command |
| T1027.013 Encrypted/Encoded File |
MalwareRedLeaves | A RedLeaves configuration file is encrypted with a simple XOR key, 0x53. |
| T1033 System Owner/User Discovery |
MalwareRedLeaves | RedLeaves can obtain information about the logged on user both locally and for Remote Desktop sessions. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareChChes | ChChes copies itself to an .exe file with a filename that is likely intended to imitate Norton Antivirus but has several letters reversed (e.g. notron.exe). |
| T1046 Network Service Discovery |
GroupmenuPass | menuPass has used tcping.exe, similar to Ping, to probe port status on systems of interest. |
| T1047 Windows Management Instrumentation |
GroupmenuPass | menuPass has used a modified version of pentesting script wmiexec.vbs, which logs into a remote machine using WMI. |
| T1049 System Network Connections Discovery |
MalwareRedLeaves | RedLeaves can enumerate drives and Remote Desktop sessions. |
| T1053.005 Scheduled Task |
GroupmenuPass | menuPass has used a script (atexec.py) to execute a command on a target machine via Task Scheduler. |
| T1056.001 Keylogging |
MalwareEvilGrab | EvilGrab has the capability to capture keystrokes. |
| T1059.001 PowerShell |
GroupmenuPass | menuPass uses PowerSploit to inject shellcode into PowerShell. |
| T1059.003 Windows Command Shell |
GroupmenuPass | menuPass executes commands using a command-line interface and reverse shell. The group has used a modified version of pentesting script wmiexec.vbs to execute commands. menuPass has used malicious macros embedded inside Office documents to execute files. |
| T1059.003 Windows Command Shell |
MalwareRedLeaves | RedLeaves can receive and execute commands with cmd.exe. It can also provide a reverse shell. |
| T1070.004 File Deletion |
MalwareRedLeaves | RedLeaves can delete specified files. |
| T1082 System Information Discovery |
MalwareRedLeaves | RedLeaves can gather extended system information including the hostname, OS version number, platform, memory information, time elapsed since system startup, and CPU information. |
| T1082 System Information Discovery |
MalwareChChes | ChChes collects the victim hostname, window resolution, and Microsoft Windows version. |
| T1083 File and Directory Discovery |
MalwareRedLeaves | RedLeaves can enumerate and search for files and directories. |
| T1087.002 Domain Account |
GroupmenuPass | menuPass has used the Microsoft administration tool csvde.exe to export Active Directory data. |
| T1105 Ingress Tool Transfer |
MalwareRedLeaves | RedLeaves is capable of downloading a file from a specified URL. |
| T1113 Screen Capture |
MalwareEvilGrab | EvilGrab has the capability to capture screenshots. |
| T1123 Audio Capture |
MalwareEvilGrab | EvilGrab has the capability to capture audio from a victim machine. |
| T1125 Video Capture |
MalwareEvilGrab | EvilGrab has the capability to capture video from a victim machine. |
| T1199 Trusted Relationship |
GroupmenuPass | menuPass has used legitimate access granted to Managed Service Providers in order to access victims of interest. |
| T1204.002 Malicious File |
GroupmenuPass | menuPass has attempted to get victims to open malicious files such as Windows Shortcuts (.lnk) and/or Microsoft Office documents, sent via email as part of spearphishing campaigns. |
| T1218.004 InstallUtil |
GroupmenuPass | menuPass has used |
| T1543.003 Windows Service |
MalwarePlugX | PlugX can be added as a service to establish persistence. PlugX also has a module to change service configurations as well as start, control, and delete services. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareEvilGrab | EvilGrab adds a Registry Run key for ctfmon.exe to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwarePlugX | PlugX adds Run key entries in the Registry to establish persistence. PlugX has established persistence via the registry keys `HKCU\Software\Microsoft\Windows\CurrentVersion\Run` and `HKLM\Software\Microsoft\Windows\CurrentVersion\Run`. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareRedLeaves | RedLeaves attempts to add a shortcut file in the Startup folder to achieve persistence. If this fails, it attempts to add Registry Run keys. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareChChes | ChChes establishes persistence by adding a Registry Run key. |
| T1547.009 Shortcut Modification |
MalwareRedLeaves | RedLeaves attempts to add a shortcut file in the Startup folder to achieve persistence. |
| T1553.002 Code Signing |
MalwareChChes | ChChes samples were digitally signed with a certificate originally used by Hacking Team that was later leaked and subsequently revoked. |
| T1555.003 Credentials from Web Browsers |
MalwareChChes | ChChes steals credentials stored inside Internet Explorer. |
| T1560.001 Archive via Utility |
GroupmenuPass | menuPass has compressed files before exfiltration using TAR and RAR. |
| T1566.001 Spearphishing Attachment |
GroupmenuPass | menuPass has sent malicious Office documents via email as part of spearphishing campaigns as well as executables disguised as documents. |
| T1571 Non-Standard Port |
MalwareRedLeaves | RedLeaves can use HTTP over non-standard ports, such as 995, for C2. |
| T1573.001 Symmetric Cryptography |
MalwareRedLeaves | RedLeaves has encrypted C2 traffic with RC4, previously using keys of 88888888 and babybear. |
| T1574.001 DLL |
GroupmenuPass | menuPass has used DLL side-loading to launch versions of Mimikatz and PwDump6 as well as UPPERCUT. menuPass has also used DLL search order hijacking. |
| T1574.001 DLL |
MalwarePlugX | PlugX has the ability to use DLL search order hijacking for installation on targeted systems. PlugX has also used DLL side-loading to evade anti-virus. PlugX has also used a legitimately signed executable to side-load a malicious payload within a DLL file. Cisco Talos MUSTANG PANDA PLUGX PUBLOAD MAY 2022Dell TG-3390EclecticIQ Mustang Panda PlugXEset PlugX Korplug Mustang Panda March 2022FireEye Clandestine Fox Part 2PWC Cloud Hopper Technical Annex April 2017Palo Alto PlugX June 2017Profero APT27 December 2020Proofpoint TA416 Europe March 2022Sophos Mustang Panda PLUGXSophos PlugX September 2022Stewart 2014Trend Micro DRBControl February 2020 |
| T1588.002 Tool |
GroupmenuPass | menuPass has used and modified open-source tools like Impacket, Mimikatz, and pwdump. |
| T1685 Disable or Modify Tools |
MalwareChChes | ChChes can alter the victim's proxy configuration. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.