ATT&CKReferencesBitdefender Naikon April 2021

Bitdefender Naikon April 2021

Vrabie, V. (2021, April 23). NAIKON – Traces from a Military Cyber-Espionage Operation. Retrieved June 29, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software2

Campaigns0

None recorded.

Procedure examples48

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareNebulae

Nebulae has the capability to upload collected files to C2.

T1005
Data from Local System
MalwareRainyDay

RainyDay can use a file exfiltration tool to collect recently changed files on a compromised host.

T1007
System Service Discovery
MalwareRainyDay

RainyDay can create and register a service for execution.

T1008
Fallback Channels
MalwareRainyDay

RainyDay has the ability to switch between TCP and HTTP for C2 if one method is not working.

T1018
Remote System Discovery
GroupNaikon

Naikon has used a netbios scanner for remote machine identification.

T1027.013
Encrypted/Encoded File
MalwareRainyDay

RainyDay has downloaded as a XOR-encrypted payload.

T1036.004
Masquerade Task or Service
MalwareRainyDay

RainyDay has named services and scheduled tasks to appear benign including "ChromeCheck" and "googleupdate."

T1036.004
Masquerade Task or Service
GroupNaikon

Naikon renamed a malicious service taskmgr to appear to be a legitimate version of Task Manager.

T1036.004
Masquerade Task or Service
MalwareNebulae

Nebulae has created a service named "Windows Update Agent1" to appear legitimate.

T1036.005
Match Legitimate Resource Name or Location
GroupNaikon

Naikon has disguised malicious programs as Google Chrome, Adobe, and VMware executables.

T1036.005
Match Legitimate Resource Name or Location
MalwareRainyDay

RainyDay has used names to mimic legitimate software including "vmtoolsd.exe" to spoof Vmtools.

T1036.005
Match Legitimate Resource Name or Location
MalwareNebulae

Nebulae uses functions named StartUserModeBrowserInjection and StopUserModeBrowserInjection indicating that it's trying to imitate chrome_frame_helper.dll.

T1046
Network Service Discovery
GroupNaikon

Naikon has used the LadonGo scanner to scan target networks.

T1047
Windows Management Instrumentation
GroupNaikon

Naikon has used WMIC.exe for lateral movement.

T1053.005
Scheduled Task
MalwareRainyDay

RainyDay can use scheduled tasks to achieve persistence.

T1053.005
Scheduled Task
GroupNaikon

Naikon has used schtasks.exe for lateral movement in compromised networks.

T1057
Process Discovery
MalwareRainyDay

RainyDay can enumerate processes on a target system.

T1057
Process Discovery
MalwareNebulae

Nebulae can enumerate processes on a target system.

T1059.003
Windows Command Shell
MalwareRainyDay

RainyDay can use the Windows Command Shell for execution.

T1059.003
Windows Command Shell
MalwareNebulae

Nebulae can use CMD to execute a process.

T1070.004
File Deletion
MalwareNebulae

Nebulae has the ability to delete files and directories.

T1070.004
File Deletion
MalwareRainyDay

RainyDay has the ability to uninstall itself by deleting its service and files.

T1071.001
Web Protocols
MalwareRainyDay

RainyDay can use HTTP in C2 communications.

T1074.001
Local Data Staging
MalwareRainyDay

RainyDay can use a file exfiltration tool to copy files to C:\ProgramData\Adobe\temp prior to exfiltration.

T1078.002
Domain Accounts
GroupNaikon

Naikon has used administrator credentials for lateral movement in compromised networks.

T1083
File and Directory Discovery
MalwareRainyDay

RainyDay can use a file exfiltration tool to collect recently changed files with specific extensions.

T1083
File and Directory Discovery
MalwareNebulae

Nebulae can list files and directories on a compromised host.

T1090
Proxy
MalwareRainyDay

RainyDay can use proxy tools including boost_proxy_client for reverse proxy functionality.

T1095
Non-Application Layer Protocol
MalwareNebulae

Nebulae can use TCP in C2 communications.

T1095
Non-Application Layer Protocol
MalwareRainyDay

RainyDay can use TCP in C2 communications.

T1105
Ingress Tool Transfer
MalwareRainyDay

RainyDay can download files to a compromised host.

T1105
Ingress Tool Transfer
MalwareNebulae

Nebulae can download files from C2.

T1106
Native API
MalwareNebulae

Nebulae has the ability to use CreateProcess to execute a process.

T1106
Native API
MalwareRainyDay

The file collection tool used by RainyDay can utilize native API including ReadDirectoryChangeW for folder monitoring.

T1113
Screen Capture
MalwareRainyDay

RainyDay has the ability to capture screenshots.

T1140
Deobfuscate/Decode Files or Information
MalwareRainyDay

RainyDay can decrypt its payload via a XOR key.

T1543.003
Windows Service
MalwareRainyDay

RainyDay can use services to establish persistence.

T1543.003
Windows Service
MalwareNebulae

Nebulae can create a service to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupNaikon

Naikon has modified a victim's Windows Run registry to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareNebulae

Nebulae can achieve persistence through a Registry Run key.

T1555.003
Credentials from Web Browsers
MalwareRainyDay

RainyDay can use tools to collect credentials from web browsers.

T1555.004
Windows Credential Manager
MalwareRainyDay

RainyDay can use the QuarksPwDump tool to obtain local passwords and domain cached credentials.

T1567.002
Exfiltration to Cloud Storage
MalwareRainyDay

RainyDay can use a file exfiltration tool to upload specific files to Dropbox.

T1573.001
Symmetric Cryptography
MalwareNebulae

Nebulae can use RC4 and XOR to encrypt C2 communications.

T1573.001
Symmetric Cryptography
MalwareRainyDay

RainyDay can use RC4 to encrypt C2 communications.

T1574.001
DLL
MalwareRainyDay

RainyDay can use side-loading to run malicious executables.

T1574.001
DLL
MalwareNebulae

Nebulae can use DLL side-loading to gain execution.

T1680
Local Storage Discovery
MalwareNebulae

Nebulae can discover logical drive information including the drive type, free space, and volume information.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.