ATT&CKReferencesMSTIC Nobelium Toolset May 2021

MSTIC Nobelium Toolset May 2021

MSTIC. (2021, May 28). Breaking down NOBELIUM’s latest early-stage toolset. Retrieved August 4, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software4

Campaigns0

None recorded.

Procedure examples40

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareEnvyScout

EnvyScout can collect sensitive NTLM material from a compromised host.

T1027
Obfuscated Files or Information
MalwareBoomBox

BoomBox can encrypt data using AES prior to exfiltration.

T1027.006
HTML Smuggling
MalwareEnvyScout

EnvyScout contains JavaScript code that can extract an encoded blob from its HTML body and write it to disk.

T1027.013
Encrypted/Encoded File
MalwareEnvyScout

EnvyScout can Base64 encode payloads.

T1033
System Owner/User Discovery
MalwareBoomBox

BoomBox can enumerate the username on a compromised host.

T1036
Masquerading
MalwareBoomBox

BoomBox has the ability to mask malicious data strings as PDF files.

T1036
Masquerading
MalwareEnvyScout

EnvyScout has used folder icons for malicious files to lure victims into opening them.

T1059.003
Windows Command Shell
MalwareEnvyScout

EnvyScout can use cmd.exe to execute malicious files on compromised hosts.

T1059.007
JavaScript
MalwareEnvyScout

EnvyScout can write files to disk with JavaScript using a modified version of the open-source tool FileSaver.

T1059.009
Cloud API
GroupAPT29

APT29 has leveraged the Microsoft Graph API to perform various actions across Azure and M365 environments. They have also utilized AADInternals PowerShell Modules to access the API

T1071.001
Web Protocols
MalwareBoomBox

BoomBox has used HTTP POST requests for C2.

T1071.001
Web Protocols
MalwareVaporRage

VaporRage can use HTTP to download shellcode from compromised websites.

T1082
System Information Discovery
MalwareEnvyScout

EnvyScout can determine whether the ISO payload was received by a Windows or iOS device.

T1082
System Information Discovery
MalwareBoomBox

BoomBox can enumerate the hostname, domain, and IP of a compromised host.

T1083
File and Directory Discovery
MalwareBoomBox

BoomBox can search for specific files and directories on a machine.

T1087.002
Domain Account
MalwareBoomBox

BoomBox has the ability to execute an LDAP query to enumerate the distinguished name, SAM account name, and display name for all domain users.

T1087.003
Email Account
MalwareBoomBox

BoomBox can execute an LDAP query to discover e-mail accounts for domain users.

T1102
Web Service
MalwareBoomBox

BoomBox can download files from Dropbox using a hardcoded access token.

T1105
Ingress Tool Transfer
MalwareVaporRage

VaporRage has the ability to download malicious shellcode to compromised systems.

T1105
Ingress Tool Transfer
MalwareBoomBox

BoomBox has the ability to download next stage malware components to a compromised system.

T1140
Deobfuscate/Decode Files or Information
MalwareEnvyScout

EnvyScout can deobfuscate and write malicious ISO files to disk.

T1140
Deobfuscate/Decode Files or Information
MalwareBoomBox

BoomBox can decrypt AES-encrypted files downloaded from C2.

T1140
Deobfuscate/Decode Files or Information
MalwareNativeZone

NativeZone can decrypt and decode embedded Cobalt Strike beacon stage shellcode.

T1140
Deobfuscate/Decode Files or Information
MalwareVaporRage

VaporRage can deobfuscate XOR-encoded shellcode prior to execution.

T1187
Forced Authentication
MalwareEnvyScout

EnvyScout can use protocol handlers to coax the operating system to send NTLMv2 authentication responses to attacker-controlled infrastructure.

T1204.002
Malicious File
MalwareBoomBox

BoomBox has gained execution through user interaction with a malicious file.

T1204.002
Malicious File
MalwareNativeZone

NativeZone can display an RTF document to the user to enable execution of Cobalt Strike stage shellcode.

T1204.002
Malicious File
MalwareEnvyScout

EnvyScout has been executed through malicious files attached to e-mails.

T1218.011
Rundll32
MalwareBoomBox

BoomBox can use RunDLL32 for execution.

T1218.011
Rundll32
MalwareEnvyScout

EnvyScout has the ability to proxy execution of malicious files with Rundll32.

T1480
Execution Guardrails
MalwareBoomBox

BoomBox can check its current working directory and for the presence of a specific file and terminate if specific values are not found.

T1480
Execution Guardrails
MalwareVaporRage

VaporRage has the ability to check for the presence of a specific DLL and terminate if it is not found.

T1480
Execution Guardrails
MalwareNativeZone

NativeZone can check for the presence of KM.EkeyAlmaz1C.dll and will halt execution unless it is in the same directory as the rest of the malware's components.

T1480
Execution Guardrails
MalwareEnvyScout

EnvyScout can call window.location.pathname to ensure that embedded files are being executed from the C: drive, and will terminate if they are not.

T1497.001
System Checks
MalwareNativeZone

NativeZone has checked if Vmware or VirtualBox VM is running on a compromised host.

T1547.001
Registry Run Keys / Startup Folder
MalwareBoomBox

BoomBox can establish persistence by writing the Registry value MicroNativeCacheSvc to HKCU\Software\Microsoft\Windows\CurrentVersion\Run.

T1564.001
Hidden Files and Directories
MalwareEnvyScout

EnvyScout can use hidden directories and files to hide malicious executables.

T1566.001
Spearphishing Attachment
MalwareEnvyScout

EnvyScout has been distributed via spearphishing as an email attachment.

T1567.002
Exfiltration to Cloud Storage
MalwareBoomBox

BoomBox can upload data to dedicated per-victim folders in Dropbox.

T1587.001
Malware
GroupAPT29

APT29 has used unique malware in many of their operations.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.