MSTIC. (2021, May 28). Breaking down NOBELIUM’s latest early-stage toolset. Retrieved August 4, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareEnvyScout | EnvyScout can collect sensitive NTLM material from a compromised host. |
| T1027 Obfuscated Files or Information |
MalwareBoomBox | BoomBox can encrypt data using AES prior to exfiltration. |
| T1027.006 HTML Smuggling |
MalwareEnvyScout | EnvyScout contains JavaScript code that can extract an encoded blob from its HTML body and write it to disk. |
| T1027.013 Encrypted/Encoded File |
MalwareEnvyScout | EnvyScout can Base64 encode payloads. |
| T1033 System Owner/User Discovery |
MalwareBoomBox | BoomBox can enumerate the username on a compromised host. |
| T1036 Masquerading |
MalwareBoomBox | BoomBox has the ability to mask malicious data strings as PDF files. |
| T1036 Masquerading |
MalwareEnvyScout | EnvyScout has used folder icons for malicious files to lure victims into opening them. |
| T1059.003 Windows Command Shell |
MalwareEnvyScout | EnvyScout can use cmd.exe to execute malicious files on compromised hosts. |
| T1059.007 JavaScript |
MalwareEnvyScout | EnvyScout can write files to disk with JavaScript using a modified version of the open-source tool FileSaver. |
| T1059.009 Cloud API |
GroupAPT29 | APT29 has leveraged the Microsoft Graph API to perform various actions across Azure and M365 environments. They have also utilized AADInternals PowerShell Modules to access the API |
| T1071.001 Web Protocols |
MalwareBoomBox | BoomBox has used HTTP POST requests for C2. |
| T1071.001 Web Protocols |
MalwareVaporRage | VaporRage can use HTTP to download shellcode from compromised websites. |
| T1082 System Information Discovery |
MalwareEnvyScout | EnvyScout can determine whether the ISO payload was received by a Windows or iOS device. |
| T1082 System Information Discovery |
MalwareBoomBox | BoomBox can enumerate the hostname, domain, and IP of a compromised host. |
| T1083 File and Directory Discovery |
MalwareBoomBox | BoomBox can search for specific files and directories on a machine. |
| T1087.002 Domain Account |
MalwareBoomBox | BoomBox has the ability to execute an LDAP query to enumerate the distinguished name, SAM account name, and display name for all domain users. |
| T1087.003 Email Account |
MalwareBoomBox | BoomBox can execute an LDAP query to discover e-mail accounts for domain users. |
| T1102 Web Service |
MalwareBoomBox | BoomBox can download files from Dropbox using a hardcoded access token. |
| T1105 Ingress Tool Transfer |
MalwareVaporRage | VaporRage has the ability to download malicious shellcode to compromised systems. |
| T1105 Ingress Tool Transfer |
MalwareBoomBox | BoomBox has the ability to download next stage malware components to a compromised system. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareEnvyScout | EnvyScout can deobfuscate and write malicious ISO files to disk. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareBoomBox | BoomBox can decrypt AES-encrypted files downloaded from C2. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareNativeZone | NativeZone can decrypt and decode embedded Cobalt Strike beacon stage shellcode. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareVaporRage | VaporRage can deobfuscate XOR-encoded shellcode prior to execution. |
| T1187 Forced Authentication |
MalwareEnvyScout | EnvyScout can use protocol handlers to coax the operating system to send NTLMv2 authentication responses to attacker-controlled infrastructure. |
| T1204.002 Malicious File |
MalwareBoomBox | BoomBox has gained execution through user interaction with a malicious file. |
| T1204.002 Malicious File |
MalwareNativeZone | NativeZone can display an RTF document to the user to enable execution of Cobalt Strike stage shellcode. |
| T1204.002 Malicious File |
MalwareEnvyScout | EnvyScout has been executed through malicious files attached to e-mails. |
| T1218.011 Rundll32 |
MalwareBoomBox | BoomBox can use RunDLL32 for execution. |
| T1218.011 Rundll32 |
MalwareEnvyScout | EnvyScout has the ability to proxy execution of malicious files with Rundll32. |
| T1480 Execution Guardrails |
MalwareBoomBox | BoomBox can check its current working directory and for the presence of a specific file and terminate if specific values are not found. |
| T1480 Execution Guardrails |
MalwareVaporRage | VaporRage has the ability to check for the presence of a specific DLL and terminate if it is not found. |
| T1480 Execution Guardrails |
MalwareNativeZone | NativeZone can check for the presence of KM.EkeyAlmaz1C.dll and will halt execution unless it is in the same directory as the rest of the malware's components. |
| T1480 Execution Guardrails |
MalwareEnvyScout | EnvyScout can call |
| T1497.001 System Checks |
MalwareNativeZone | NativeZone has checked if Vmware or VirtualBox VM is running on a compromised host. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareBoomBox | BoomBox can establish persistence by writing the Registry value |
| T1564.001 Hidden Files and Directories |
MalwareEnvyScout | EnvyScout can use hidden directories and files to hide malicious executables. |
| T1566.001 Spearphishing Attachment |
MalwareEnvyScout | EnvyScout has been distributed via spearphishing as an email attachment. |
| T1567.002 Exfiltration to Cloud Storage |
MalwareBoomBox | BoomBox can upload data to dedicated per-victim folders in Dropbox. |
| T1587.001 Malware |
GroupAPT29 | APT29 has used unique malware in many of their operations. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.