Sherstobitoff, R., Saavedra-Morales, J. (2018, February 02). Gold Dragon Widens Olympics Malware Attacks, Gains Permanent Presence on Victims’ Systems. Retrieved June 6, 2018.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1012 Query Registry |
MalwareGold Dragon | Gold Dragon enumerates registry keys with the command |
| T1012 Query Registry |
MalwareBrave Prince | Brave Prince gathers information about the Registry. |
| T1016 System Network Configuration Discovery |
MalwareBrave Prince | Brave Prince gathers network configuration information as well as the ARP cache. |
| T1033 System Owner/User Discovery |
MalwareGold Dragon | Gold Dragon collects the endpoint victim's username and uses it as a basis for downloading additional components from the C2 server. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareBrave Prince | Some Brave Prince variants have used South Korea's Daum email service to exfiltrate information, and later variants have posted the data to a web server via an HTTP post command. |
| T1056.001 Keylogging |
MalwareRunningRAT | RunningRAT captures keystrokes and sends them back to the C2 server. |
| T1057 Process Discovery |
MalwareGold Dragon | Gold Dragon checks the running processes on the victim’s machine. |
| T1057 Process Discovery |
MalwareBrave Prince | Brave Prince lists the running processes. |
| T1059.003 Windows Command Shell |
MalwareRunningRAT | RunningRAT uses a batch file to kill a security program task and then attempts to remove itself. |
| T1059.003 Windows Command Shell |
MalwareGold Dragon | Gold Dragon uses cmd.exe to execute commands for discovery. |
| T1070.004 File Deletion |
MalwareRunningRAT | RunningRAT contains code to delete files from the victim’s machine. |
| T1070.004 File Deletion |
MalwareGold Dragon | Gold Dragon deletes one of its files, 2.hwp, from the endpoint after establishing persistence. |
| T1071.001 Web Protocols |
MalwareGold Dragon | Gold Dragon uses HTTP for communication to the control servers. |
| T1074.001 Local Data Staging |
MalwareGold Dragon | Gold Dragon stores information gathered from the endpoint in a file named 1.hwp. |
| T1082 System Information Discovery |
MalwareRunningRAT | RunningRAT gathers the OS version and processor information. |
| T1082 System Information Discovery |
MalwareBrave Prince | Brave Prince collects hard drive content and system configuration information. |
| T1082 System Information Discovery |
MalwareGold Dragon | Gold Dragon collects endpoint information using the |
| T1083 File and Directory Discovery |
MalwareGold Dragon | Gold Dragon lists the directories for Desktop, program files, and the user’s recently accessed files. |
| T1083 File and Directory Discovery |
MalwareBrave Prince | Brave Prince gathers file and directory information from the victim’s machine. |
| T1105 Ingress Tool Transfer |
MalwareGold Dragon | Gold Dragon can download additional components from the C2 server. |
| T1115 Clipboard Data |
MalwareRunningRAT | RunningRAT contains code to open and copy data from the clipboard. |
| T1518.001 Security Software Discovery |
MalwareGold Dragon | Gold Dragon checks for anti-malware products and processes. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareGold Dragon | Gold Dragon establishes persistence in the Startup folder. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareRunningRAT | RunningRAT adds itself to the Registry key |
| T1560 Archive Collected Data |
MalwareRunningRAT | RunningRAT contains code to compress files. |
| T1560 Archive Collected Data |
MalwareGold Dragon | Gold Dragon encrypts data using Base64 before being sent to the command and control server. |
| T1680 Local Storage Discovery |
MalwareRunningRAT | RunningRAT gathers logical drives information and volume information. |
| T1685 Disable or Modify Tools |
MalwareGold Dragon | Gold Dragon terminates anti-malware processes if they’re found running on the system. |
| T1685 Disable or Modify Tools |
MalwareBrave Prince | Brave Prince terminates antimalware processes. |
| T1685 Disable or Modify Tools |
MalwareRunningRAT | RunningRAT kills antimalware running process. |
| T1685.005 Clear Windows Event Logs |
MalwareRunningRAT | RunningRAT contains code to clear event logs. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.