ATT&CKReferencesPWC Yellow Liderc 2023

PWC Yellow Liderc 2023

PwC Threat Intelligence. (2023, October 25). Yellow Liderc ships its scripts and delivers IMAPLoader malware. Retrieved August 14, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples21

TechniqueUsed byProcedure example
T1041
Exfiltration Over C2 Channel
GroupCURIUM

CURIUM has used IMAP and SMTPS for exfiltration via tools such as IMAPLoader.

T1047
Windows Management Instrumentation
MalwareIMAPLoader

IMAPLoader uses WMI queries to query system information on victim hosts.

T1048.002
Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
GroupCURIUM

CURIUM has used SMTPS to exfiltrate collected data from victims.

T1053.005
Scheduled Task
MalwareIMAPLoader

IMAPLoader creates scheduled tasks for persistence based on the operating system version of the victim machine.

T1071.003
Mail Protocols
MalwareIMAPLoader

IMAPLoader uses the IMAP email protocol for command and control purposes.

T1082
System Information Discovery
MalwareIMAPLoader

IMAPLoader uses WMI queries to gather information about the victim machine.

T1105
Ingress Tool Transfer
MalwareIMAPLoader

IMAPLoader is a loader used to retrieve follow-on payload encoded in email messages for execution on victim systems.

T1106
Native API
MalwareIMAPLoader

IMAPLoader imports native Windows APIs such as `GetConsoleWindow` and `ShowWindow`.

T1124
System Time Discovery
GroupCURIUM

CURIUM deployed mechanisms to check system time information following strategic website compromise attacks.

T1189
Drive-by Compromise
GroupCURIUM

CURIUM has used strategic website compromise to infect victims with malware such as IMAPLoader.

T1543
Create or Modify System Process
MalwareIMAPLoader

IMAPLoader modifies Windows tasks on the victim machine to reference a retrieved PE file through a path modification.

T1564.003
Hidden Window
MalwareIMAPLoader

IMAPLoader hides the Windows Console window created by its execution by directly importing the `kernel32.dll` and `user32.dll` libraries `GetConsoleWindow` and `ShowWindow` APIs.

T1566.001
Spearphishing Attachment
GroupCURIUM

CURIUM has used phishing with malicious attachments for initial access to victim environments.

T1574.014
AppDomainManager
MalwareIMAPLoader

IMAPLoader is executed via the AppDomainManager injection technique.

T1583.001
Domains
GroupCURIUM

CURIUM created domains to facilitate strategic website compromise and credential capture activities.

T1583.003
Virtual Private Server
GroupCURIUM

CURIUM created virtual private server instances to facilitate use of malicious domains and other items.

T1583.004
Server
GroupCURIUM

CURIUM has created dedicated servers for command and control and exfiltration purposes.

T1584.006
Web Services
GroupCURIUM

CURIUM has compromised legitimate websites to enable strategic website compromise attacks.

T1585.002
Email Accounts
GroupCURIUM

CURIUM has created dedicated email accounts for use with tools such as IMAPLoader.

T1598.003
Spearphishing Link
GroupCURIUM

CURIUM used malicious links to adversary-controlled resources for credential harvesting.

T1608.004
Drive-by Target
GroupCURIUM

CURIUM used strategic website compromise to fingerprint then target victims.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.