ATT&CKReferencesMandiant Cutting Edge Part 2 January 2024

Mandiant Cutting Edge Part 2 January 2024

Lin, M. et al. (2024, January 31). Cutting Edge, Part 2: Investigating Ivanti Connect Secure VPN Zero-Day Exploitation. Retrieved February 27, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software4

Campaigns1

Procedure examples35

TechniqueUsed byProcedure example
T1001
Data Obfuscation
MalwareFRAMESTING

FRAMESTING can send and receive zlib compressed data within `POST` requests.

T1001.003
Protocol or Service Impersonation
MalwareFRAMESTING

FRAMESTING uses a cookie named `DSID` to mimic the name of a cookie used by Ivanti Connect Secure appliances for maintaining VPN sessions.

T1005
Data from Local System
CampaignCutting Edge

During Cutting Edge, threat actors stole the running configuration and cache data from targeted Ivanti Connect Secure VPNs.

T1027
Obfuscated Files or Information
MalwareBUSHWALK

BUSHWALK can encrypt the resulting data generated from C2 commands with RC4.

T1027.013
Encrypted/Encoded File
CampaignCutting Edge

During Cutting Edge, threat actors used a Base64-encoded Python script to write a patched version of the Ivanti Connect Secure `dsls` binary.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwareWARPWIRE

WARPWIRE can send captured credentials to C2 via HTTP `GET` or `POST` requests.

T1059
Command and Scripting Interpreter
CampaignCutting Edge

During Cutting Edge, threat actors used Perl scripts to enable the deployment of the THINSPOOL shell script dropper and for enumerating host data.

T1059.006
Python
MalwareFRAMESTING

FRAMESTING is a Python web shell that can embed in the Ivanti Connect Secure CAV Python package.

T1070
Indicator Removal
CampaignCutting Edge

During Cutting Edge, threat actors cleared logs to remove traces of their activity and restored compromised systems to a clean state to bypass manufacturer mitigations for CVE-2023-46805 and CVE-2024-21887.

T1070.004
File Deletion
CampaignCutting Edge

During Cutting Edge, threat actors deleted `/tmp/test1.txt` on compromised Ivanti Connect Secure VPNs which was used to hold stolen configuration and cache files.

T1070.006
Timestomp
CampaignCutting Edge

During Cutting Edge, threat actors changed timestamps of multiple files on compromised Ivanti Secure Connect VPNs to conceal malicious activity.

T1071.001
Web Protocols
MalwareFRAMESTING

FRAMESTING can retrieve C2 commands from values stored in the `DSID` cookie from the current HTTP request or from decompressed zlib data within the request's `POST` data.

T1071.001
Web Protocols
MalwareLIGHTWIRE

LIGHTWIRE can use HTTP for C2 communications.

T1071.004
DNS
CampaignCutting Edge

During Cutting Edge, threat actors used DNS to tunnel IPv4 C2 traffic.

T1082
System Information Discovery
CampaignCutting Edge

During Cutting Edge, threat actors used the ENUM4LINUX Perl script for discovery on Windows and Samba hosts.

T1090
Proxy
MalwareZIPLINE

ZIPLINE can create a proxy server on compromised hosts.

T1095
Non-Application Layer Protocol
MalwareZIPLINE

ZIPLINE can communicate with C2 using a custom binary protocol.

T1105
Ingress Tool Transfer
MalwareZIPLINE

ZIPLINE can download files to be saved on the compromised system.

T1105
Ingress Tool Transfer
MalwareBUSHWALK

BUSHWALK can write malicious payloads sent through a web request’s command parameter.

T1140
Deobfuscate/Decode Files or Information
MalwareFRAMESTING

FRAMESTING can decompress data received within `POST` requests.

T1140
Deobfuscate/Decode Files or Information
MalwareBUSHWALK

BUSHWALK can Base64 decode and RC4 decrypt malicious payloads sent through a web request’s command parameter.

T1140
Deobfuscate/Decode Files or Information
MalwareLIGHTWIRE

LIGHTWIRE can RC4 decrypt and Base64 decode C2 commands.

T1190
Exploit Public-Facing Application
CampaignCutting Edge

During Cutting Edge, threat actors exploited CVE-2023-46805 and CVE-2024-21887 in Ivanti Connect Secure VPN appliances to enable authentication bypass and command injection. A server-side request forgery (SSRF) vulnerability, CVE-2024-21893, was identified later and used to bypass mitigations for the initial two vulnerabilities by chaining with CVE-2024-21887.

T1505.003
Web Shell
MalwareLIGHTWIRE

LIGHTWIRE is a web shell capable of command execution and establishing persistence on compromised Ivanti Secure Connect VPNs.

T1505.003
Web Shell
MalwareBUSHWALK

BUSHWALK is a web shell that has the ability to execute arbitrary commands or write files.

T1505.003
Web Shell
MalwareFRAMESTING

FRAMESTING is a web shell capable of enabling arbitrary command execution on compromised Ivanti Connect Secure VPNs.

T1554
Compromise Host Software Binary
MalwareLIGHTWIRE

LIGHTWIRE can imbed itself into the legitimate `compcheckresult.cgi` component of Ivanti Connect Secure VPNs to enable command execution.

T1554
Compromise Host Software Binary
MalwareFRAMESTING

FRAMESTING can embed itself in the CAV Python package of an Ivanti Connect Secure VPN located in `/home/venv3/lib/python3.6/site-packages/cav-0.1-py3.6.egg/cav/api/resources/category.py.`

T1554
Compromise Host Software Binary
CampaignCutting Edge

During Cutting Edge, threat actors trojanized legitimate files in Ivanti Connect Secure appliances with malicious code.

T1554
Compromise Host Software Binary
MalwareBUSHWALK

BUSHWALK can embed into the legitimate `querymanifest.cgi` file on compromised Ivanti Connect Secure VPNs.

T1560.001
Archive via Utility
CampaignCutting Edge

During Cutting Edge, threat actors saved collected data to a tar archive.

T1572
Protocol Tunneling
CampaignCutting Edge

During Cutting Edge, threat actors used Iodine to tunnel IPv4 traffic over DNS.

T1573.001
Symmetric Cryptography
MalwareZIPLINE

ZIPLINE can use AES-128-CBC to encrypt data for both upload and download.

T1573.001
Symmetric Cryptography
MalwareLIGHTWIRE

LIGHTWIRE can RC4 encrypt C2 commands.

T1685
Disable or Modify Tools
CampaignCutting Edge

During Cutting Edge, threat actors disabled logging and modified the `compcheckresult.cgi` component to edit the Ivanti Connect Secure built-in Integrity Checker exclusion list to evade detection.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.