ATT&CKReferencesVolexity UPSTYLE 2024

Volexity UPSTYLE 2024

Volexity Threat Research. (2024, April 12). Zero-Day Exploitation of Unauthenticated Remote Code Execution Vulnerability in GlobalProtect (CVE-2024-3400). Retrieved November 20, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns1

Procedure examples27

TechniqueUsed byProcedure example
T1001.001
Junk Data
MalwareUPSTYLE

UPSTYLE retrieves a non-existent webpage from the command and control server then parses commands from the resulting error logs to decode commands to the web shell.

T1003.003
NTDS
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors obtained active directory credentials via the NTDS.DIT file.

T1005
Data from Local System
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors stole saved cookies and login data from targeted systems.

T1021.002
SMB/Windows Admin Shares
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors used SMB to pivot internally in victim networks.

T1021.006
Windows Remote Management
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors used WinRM to move laterally in targeted networks.

T1027.013
Encrypted/Encoded File
MalwareUPSTYLE

UPSTYLE stores primary content as base64-encoded objects.

T1036
Masquerading
MalwareUPSTYLE

UPSTYLE has masqueraded filenames using examples such as `update.py`.

T1053.003
Cron
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors configured cron jobs to retrieve payloads from actor-controlled infrastructure.

T1059.004
Unix Shell
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors piped output from stdout to bash for execution.

T1059.006
Python
MalwareUPSTYLE

UPSTYLE is a Python-based application.

T1070.004
File Deletion
MalwareUPSTYLE

UPSTYLE removes `bootstrap.min.css` after parsing command and control instructions, restoring the file to its original state.

T1070.006
Timestomp
MalwareUPSTYLE

UPSTYLE restores timestamps to original values following modification.

T1071.001
Web Protocols
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors used `wget` via HTTP to retrieve payloads.

T1078
Valid Accounts
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors extracted sensitive credentials while moving laterally through compromised networks.

T1078.002
Domain Accounts
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors used a compromised domain admin account to move laterally.

T1090
Proxy
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors used the GO Simple Tunnel reverse proxy tool.

T1102.003
One-Way Communication
MalwareUPSTYLE

UPSTYLE parses encoded commands from error logs after attempting to resolve a non-existing webpage from the command and control server.

T1105
Ingress Tool Transfer
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors downloaded additional payloads on compromised devices.

T1140
Deobfuscate/Decode Files or Information
MalwareUPSTYLE

UPSTYLE encodes its main content prior to loading via Python as base64-encoded blobs.

T1190
Exploit Public-Facing Application
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors exploited CVE-2024-3400 in Palo Alto Networks GlobalProtect.

T1546
Event Triggered Execution
MalwareUPSTYLE

UPSTYLE creates a `.pth` file beginning with the text `import` so that any time another process or script attempts to reference the modified item the malicious code will also run.

T1559
Inter-Process Communication
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors wrote output to stdout then piped it to bash for execution.

T1584.003
Virtual Private Server
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors abused Virtual Private Servers to store malicious files.

T1584.006
Web Services
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors abused compromised AWS buckets to store files.

T1588.002
Tool
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors used the GO Simple Tunnel (GOST) reverse proxy tool.

T1665
Hide Infrastructure
MalwareUPSTYLE

UPSTYLE attempts to retrieve a non-existent webpage from the command and control server resulting in hidden commands sent via resulting error messages.

T1685.006
Clear Linux or Mac System Logs
MalwareUPSTYLE

UPSTYLE clears error logs after reading embedded commands for execution.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.