ATT&CKReferencesPWC WellMess July 2020

PWC WellMess July 2020

PWC. (2020, July 16). How WellMess malware has been used to target COVID-19 vaccines. Retrieved September 24, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples13

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareWellMess

WellMess can send files from the victim machine to C2.

T1016
System Network Configuration Discovery
MalwareWellMess

WellMess can identify the IP address and user domain on the target machine.

T1059.001
PowerShell
MalwareWellMess

WellMess can execute PowerShell scripts received from C2.

T1059.003
Windows Command Shell
MalwareWellMess

WellMess can execute command line scripts received from C2.

T1071.001
Web Protocols
MalwareWellMess

WellMess can use HTTP and HTTPS in C2 communications.

T1071.004
DNS
MalwareWellMess

WellMess has the ability to use DNS tunneling for C2 communications.

T1082
System Information Discovery
MalwareWellMess

WellMess can identify the computer name of a compromised host.

T1105
Ingress Tool Transfer
MalwareWellMess

WellMess can write files to a compromised host.

T1105
Ingress Tool Transfer
GroupAPT29

APT29 has downloaded additional tools and malware onto compromised networks.

T1140
Deobfuscate/Decode Files or Information
MalwareWellMess

WellMess can decode and decrypt data received from C2.

T1573.001
Symmetric Cryptography
MalwareWellMess

WellMess can encrypt HTTP POST data using RC6 and a dynamically generated AES key encrypted with a hard coded RSA public key.

T1573.002
Asymmetric Cryptography
MalwareWellMess

WellMess can communicate to C2 with mutual TLS where client and server mutually check certificates.

T1587.003
Digital Certificates
GroupAPT29

APT29 has created self-signed digital certificates to enable mutual TLS authentication for malware.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.