ATT&CKReferencesNCSC APT29 July 2020

NCSC APT29 July 2020

National Cyber Security Centre. (2020, July 16). Advisory: APT29 targets COVID-19 vaccine development. Retrieved September 29, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software3

Campaigns0

None recorded.

Procedure examples9

TechniqueUsed byProcedure example
T1071.001
Web Protocols
MalwareWellMess

WellMess can use HTTP and HTTPS in C2 communications.

T1071.001
Web Protocols
MalwareSoreFang

SoreFang can use HTTP in C2 communications.

T1071.004
DNS
MalwareWellMess

WellMess has the ability to use DNS tunneling for C2 communications.

T1105
Ingress Tool Transfer
MalwareSoreFang

SoreFang can download additional payloads from C2.

T1133
External Remote Services
GroupAPT29

APT29 has used compromised identities to access networks via VPNs and Citrix.

T1190
Exploit Public-Facing Application
GroupAPT29

APT29 has exploited CVE-2019-19781 for Citrix, CVE-2019-11510 for Pulse Secure VPNs, CVE-2018-13379 for FortiGate VPNs, and CVE-2019-9670 in Zimbra software to gain access.

T1571
Non-Standard Port
MalwareWellMail

WellMail has been observed using TCP port 25, without using SMTP, to leverage an open port for secure command and control communications.

T1573.002
Asymmetric Cryptography
MalwareWellMail

WellMail can use hard coded client and certificate authority certificates to communicate with C2 over mutual TLS.

T1573.002
Asymmetric Cryptography
MalwareWellMess

WellMess can communicate to C2 with mutual TLS where client and server mutually check certificates.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.