ATT&CKReferencesCheckPoint Naikon May 2020

CheckPoint Naikon May 2020

CheckPoint. (2020, May 7). Naikon APT: Cyber Espionage Reloaded. Retrieved May 26, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples28

TechniqueUsed byProcedure example
T1010
Application Window Discovery
MalwareAria-body

Aria-body has the ability to identify the titles of running windows on a compromised host.

T1016
System Network Configuration Discovery
MalwareAria-body

Aria-body has the ability to identify the location, public IP address, and domain name on a compromised host.

T1025
Data from Removable Media
MalwareAria-body

Aria-body has the ability to collect data from USB devices.

T1027.013
Encrypted/Encoded File
MalwareAria-body

Aria-body has used an encrypted configuration file for its loader.

T1033
System Owner/User Discovery
MalwareAria-body

Aria-body has the ability to identify the username on a compromised host.

T1049
System Network Connections Discovery
MalwareAria-body

Aria-body has the ability to gather TCP and UDP table status listings.

T1055.001
Dynamic-link Library Injection
MalwareAria-body

Aria-body has the ability to inject itself into another process such as rundll32.exe and dllhost.exe.

T1057
Process Discovery
MalwareAria-body

Aria-body has the ability to enumerate loaded modules for a process..

T1070.004
File Deletion
MalwareAria-body

Aria-body has the ability to delete files and directories on compromised hosts.

T1071.001
Web Protocols
MalwareAria-body

Aria-body has used HTTP in C2 communications.

T1082
System Information Discovery
MalwareAria-body

Aria-body has the ability to identify the hostname, computer name, Windows version, processor speed, and machine GUID on a compromised host.

T1083
File and Directory Discovery
MalwareAria-body

Aria-body has the ability to gather metadata from a file and to search for file and directory names.

T1090
Proxy
MalwareAria-body

Aria-body has the ability to use a reverse SOCKS proxy module.

T1095
Non-Application Layer Protocol
MalwareAria-body

Aria-body has used TCP in C2 communications.

T1105
Ingress Tool Transfer
MalwareAria-body

Aria-body has the ability to download additional payloads from C2.

T1106
Native API
MalwareAria-body

Aria-body has the ability to launch files using ShellExecute.

T1113
Screen Capture
MalwareAria-body

Aria-body has the ability to capture screenshots on compromised hosts.

T1134.001
Token Impersonation/Theft
MalwareAria-body

Aria-body has the ability to duplicate a token from ntprint.exe.

T1134.002
Create Process with Token
MalwareAria-body

Aria-body has the ability to execute a process using runas.

T1137.006
Add-ins
GroupNaikon

Naikon has used the RoyalRoad exploit builder to drop a second stage loader, intel.wll, into the Word Startup folder on the compromised host.

T1140
Deobfuscate/Decode Files or Information
MalwareAria-body

Aria-body has the ability to decrypt the loader configuration and payload DLL.

T1204.002
Malicious File
GroupNaikon

Naikon has convinced victims to open malicious attachments to execute malware.

T1547.001
Registry Run Keys / Startup Folder
MalwareAria-body

Aria-body has established persistence via the Startup folder or Run Registry key.

T1560
Archive Collected Data
MalwareAria-body

Aria-body has used ZIP to compress data gathered on a compromised host.

T1566.001
Spearphishing Attachment
GroupNaikon

Naikon has used malicious e-mail attachments to deliver malware.

T1568.002
Domain Generation Algorithms
MalwareAria-body

Aria-body has the ability to use a DGA for C2 communications.

T1574.001
DLL
GroupNaikon

Naikon has used DLL side-loading to load malicious DLL's into legitimate executables.

T1680
Local Storage Discovery
MalwareAria-body

Aria-body has the ability to identify disk information on a compromised host.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.