ATT&CKReferencesSecurelist APT10 March 2021

Securelist APT10 March 2021

GREAT. (2021, March 30). APT10: sophisticated multi-layered loader Ecipekac discovered in A41APT campaign. Retrieved June 17, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software4

Campaigns0

None recorded.

Procedure examples30

TechniqueUsed byProcedure example
T1001.001
Junk Data
MalwareP8RAT

P8RAT can send randomly-generated data as part of its C2 communication.

T1012
Query Registry
MalwareSodaMaster

SodaMaster has the ability to query the Registry to detect a key specific to VMware.

T1027
Obfuscated Files or Information
MalwareEcipekac

Ecipekac can use XOR, AES, and DES to encrypt loader shellcode.

T1027
Obfuscated Files or Information
MalwareSodaMaster

SodaMaster can use "stackstrings" for obfuscation.

T1027.002
Software Packing
MalwareFYAnti

FYAnti has used ConfuserEx to pack its .NET module.

T1033
System Owner/User Discovery
MalwareSodaMaster

SodaMaster can identify the username on a compromised host.

T1057
Process Discovery
MalwareSodaMaster

SodaMaster can search a list of running processes.

T1057
Process Discovery
MalwareP8RAT

P8RAT can check for specific processes associated with virtual environments.

T1070.003
Clear Command History
GroupmenuPass

menuPass has used Wevtutil to remove PowerShell execution logs.

T1071.001
Web Protocols
MalwareCobalt Strike

Cobalt Strike can use a custom command and control protocol that can be encapsulated in HTTP or HTTPS. All protocols use their standard assigned ports.

T1078
Valid Accounts
GroupmenuPass

menuPass has used valid accounts including shared between Managed Service Providers and clients to move between the two environments.

T1082
System Information Discovery
MalwareSodaMaster

SodaMaster can enumerate the host name and OS version on a target system.

T1083
File and Directory Discovery
MalwareFYAnti

FYAnti can search the C:\Windows\Microsoft.NET\ directory for files of a specified size.

T1105
Ingress Tool Transfer
MalwareP8RAT

P8RAT can download additional payloads to a target system.

T1105
Ingress Tool Transfer
MalwareEcipekac

Ecipekac can download additional payloads to a compromised host.

T1105
Ingress Tool Transfer
MalwareFYAnti

FYAnti can download additional payloads to a compromised host.

T1105
Ingress Tool Transfer
MalwareSodaMaster

SodaMaster has the ability to download additional payloads from C2 to the targeted system.

T1106
Native API
MalwareSodaMaster

SodaMaster can use RegOpenKeyW to access the Registry.

T1140
Deobfuscate/Decode Files or Information
MalwareFYAnti

FYAnti has the ability to decrypt an embedded .NET module.

T1140
Deobfuscate/Decode Files or Information
MalwareEcipekac

Ecipekac has the ability to decrypt fileless loader modules.

T1190
Exploit Public-Facing Application
GroupmenuPass

menuPass has leveraged vulnerabilities in Pulse Secure VPNs to hijack sessions.

T1497.001
System Checks
MalwareSodaMaster

SodaMaster can check for the presence of the Registry key HKEY_CLASSES_ROOT\\Applications\\VMwareHostOpen.exe before proceeding to its main functionality.

T1497.001
System Checks
MalwareP8RAT

P8RAT can check the compromised host for processes associated with VMware or VirtualBox environments.

T1497.003
Time Based Checks
MalwareP8RAT

P8RAT has the ability to "sleep" for a specified time to evade detection.

T1497.003
Time Based Checks
MalwareSodaMaster

SodaMaster has the ability to put itself to "sleep" for a specified time.

T1553.002
Code Signing
GroupmenuPass

menuPass has resized and added data to the certificate table to enable the signing of modified files with legitimate signatures.

T1553.002
Code Signing
MalwareEcipekac

Ecipekac has used a valid, legitimate digital signature to evade detection.

T1573.001
Symmetric Cryptography
MalwareSodaMaster

SodaMaster can use RC4 to encrypt C2 communications.

T1573.002
Asymmetric Cryptography
MalwareSodaMaster

SodaMaster can use a hardcoded RSA key to encrypt some of its C2 traffic.

T1574.001
DLL
MalwareEcipekac

Ecipekac can abuse the legitimate application policytool.exe to load a malicious DLL.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.