National Cyber Security Centre. (2020, July 16). Advisory: APT29 targets COVID-19 vaccine development. Retrieved September 29, 2020.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1071.001 Web Protocols |
MalwareWellMess | WellMess can use HTTP and HTTPS in C2 communications. |
| T1071.001 Web Protocols |
MalwareSoreFang | SoreFang can use HTTP in C2 communications. |
| T1071.004 DNS |
MalwareWellMess | WellMess has the ability to use DNS tunneling for C2 communications. |
| T1105 Ingress Tool Transfer |
MalwareSoreFang | SoreFang can download additional payloads from C2. |
| T1133 External Remote Services |
GroupAPT29 | APT29 has used compromised identities to access networks via VPNs and Citrix. |
| T1190 Exploit Public-Facing Application |
GroupAPT29 | APT29 has exploited CVE-2019-19781 for Citrix, CVE-2019-11510 for Pulse Secure VPNs, CVE-2018-13379 for FortiGate VPNs, and CVE-2019-9670 in Zimbra software to gain access. |
| T1571 Non-Standard Port |
MalwareWellMail | WellMail has been observed using TCP port 25, without using SMTP, to leverage an open port for secure command and control communications. |
| T1573.002 Asymmetric Cryptography |
MalwareWellMail | WellMail can use hard coded client and certificate authority certificates to communicate with C2 over mutual TLS. |
| T1573.002 Asymmetric Cryptography |
MalwareWellMess | WellMess can communicate to C2 with mutual TLS where client and server mutually check certificates. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.