ATT&CKReferencesMcAfee Oceansalt Oct 2018

McAfee Oceansalt Oct 2018

Sherstobitoff, R., Malhotra, A. (2018, October 18). ‘Operation Oceansalt’ Attacks South Korea, U.S., and Canada With Source Code From Chinese Hacker Group. Retrieved November 30, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software2

Campaigns0

None recorded.

Procedure examples10

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareOceanSalt

OceanSalt can collect the victim’s IP address.

T1057
Process Discovery
MalwareOceanSalt

OceanSalt can collect the name and ID for every process running on the system.

T1059.003
Windows Command Shell
MalwareOceanSalt

OceanSalt can create a reverse shell on the infected endpoint using cmd.exe. OceanSalt has been executed via malicious macros.

T1070.004
File Deletion
MalwareOceanSalt

OceanSalt can delete files from the system.

T1082
System Information Discovery
MalwareOceanSalt

OceanSalt can collect the computer name from the system.

T1083
File and Directory Discovery
MalwareOceanSalt

OceanSalt can extract drive information from the endpoint and search files on the system.

T1083
File and Directory Discovery
MalwareSeasalt

Seasalt has the capability to identify the drive type on a victim.

T1132.002
Non-Standard Encoding
MalwareOceanSalt

OceanSalt can encode data with a NOT operation before sending the data to the control server.

T1547.001
Registry Run Keys / Startup Folder
MalwareSeasalt

Seasalt creates a Registry entry to ensure infection after reboot under HKLM\Software\Microsoft\Windows\currentVersion\Run.

T1566.001
Spearphishing Attachment
MalwareOceanSalt

OceanSalt has been delivered via spearphishing emails with Microsoft Office attachments.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.