ATT&CKReferencesSymantec Crambus OCT 2023

Symantec Crambus OCT 2023

Symantec Threat Hunter Team. (2023, October 19). Crambus: New Campaign Targets Middle Eastern Government. Retrieved November 27, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples19

TechniqueUsed byProcedure example
T1021.001
Remote Desktop Protocol
GroupOilRig

OilRig has used Remote Desktop Protocol for lateral movement. The group has also used tunneling tools to tunnel RDP into the environment.

T1025
Data from Removable Media
GroupOilRig

OilRig has used Wireshark’s usbcapcmd utility to capture USB traffic.

T1036.005
Match Legitimate Resource Name or Location
GroupOilRig

OilRig has named a downloaded copy of the Plink tunneling utility as \ProgramData\Adobe.exe.

T1041
Exfiltration Over C2 Channel
MalwarePowerExchange

PowerExchange can exfiltrate files via its email C2 channel.

T1047
Windows Management Instrumentation
GroupOilRig

OilRig has used WMI for execution.

T1056.001
Keylogging
GroupOilRig

OilRig has employed keyloggers including KEYPUNCH and LONGWATCH.

T1057
Process Discovery
GroupOilRig

OilRig has run tasklist on a victim's machine and used infostealers to capture processes.

T1059.001
PowerShell
MalwarePowerExchange

PowerExchange can use PowerShell to execute commands received from C2.

T1069.001
Local Groups
GroupOilRig

OilRig has used net localgroup administrators to find local administrators on compromised systems.

T1071.003
Mail Protocols
MalwarePowerExchange

PowerExchange can receive and send back the results of executed C2 commands through email.

T1082
System Information Discovery
GroupOilRig

OilRig has run hostname and systeminfo on a victim.

T1105
Ingress Tool Transfer
MalwarePowerExchange

PowerExchange can decode Base64-encoded files and call `WriteAllBytes` to write the files to compromised hosts.

T1112
Modify Registry
GroupOilRig

OilRig has used reg.exe to modify system configuration.

T1115
Clipboard Data
GroupOilRig

OilRig has used infostealer tools to copy clipboard data.

T1140
Deobfuscate/Decode Files or Information
MalwarePowerExchange

PowerExchange can decode and decrypt C2 commands received via email.

T1543.003
Windows Service
GroupOilRig

OilRig has used a compromised Domain Controller to create a service on a remote host.

T1572
Protocol Tunneling
GroupOilRig

OilRig has used the Plink utility and other tools to create tunnels to C2 servers.

T1588.002
Tool
GroupOilRig

OilRig has made use of the publicly available tools including Plink and Mimikatz.

T1686.003
Windows Host Firewall
GroupOilRig

OilRig has modified Windows firewall rules to enable remote access.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.