Faou, M., Tartare, M., Dupuy, T. (2019, October). OPERATION GHOST. Retrieved September 23, 2020.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1001.002 Steganography |
CampaignOperation Ghost | During Operation Ghost, APT29 used steganography to hide the communications between the implants and their C&C servers. |
| T1005 Data from Local System |
MalwareFatDuke | FatDuke can copy files and directories from a compromised host. |
| T1008 Fallback Channels |
MalwareFatDuke | FatDuke has used several C2 servers per targeted organization. |
| T1012 Query Registry |
MalwareFatDuke | FatDuke can get user agent strings for the default browser from |
| T1012 Query Registry |
MalwareLiteDuke | LiteDuke can query the Registry to check for the presence of |
| T1016 System Network Configuration Discovery |
MalwareLiteDuke | LiteDuke has the ability to discover the proxy configuration of Firefox and/or Opera. |
| T1016 System Network Configuration Discovery |
MalwareFatDuke | FatDuke can identify the MAC address on the target computer. |
| T1027 Obfuscated Files or Information |
MalwareMiniDuke | MiniDuke can use control flow flattening to obscure code. |
| T1027 Obfuscated Files or Information |
MalwareFatDuke | FatDuke can use base64 encoding, string stacking, and opaque predicates for obfuscation. |
| T1027 Obfuscated Files or Information |
MalwarePolyglotDuke | PolyglotDuke can custom encrypt strings. |
| T1027 Obfuscated Files or Information |
MalwareRegDuke | RegDuke can use control-flow flattening or the commercially available .NET Reactor for obfuscation. |
| T1027.002 Software Packing |
MalwareLiteDuke | LiteDuke has been packed with multiple layers of encryption. |
| T1027.002 Software Packing |
MalwareFatDuke | FatDuke has been regularly repacked by its operators to create large binaries and evade detection. |
| T1027.003 Steganography |
MalwareLiteDuke | LiteDuke has used image files to hide its loader component. |
| T1027.003 Steganography |
MalwarePolyglotDuke | PolyglotDuke can use steganography to hide C2 information in images. |
| T1027.003 Steganography |
CampaignOperation Ghost | During Operation Ghost, APT29 used steganography to hide payloads inside valid images. |
| T1027.003 Steganography |
MalwareRegDuke | RegDuke can hide data in images, including use of the Least Significant Bit (LSB). |
| T1027.011 Fileless Storage |
MalwareRegDuke | RegDuke can store its encryption key in the Registry. |
| T1027.011 Fileless Storage |
MalwarePolyglotDuke | PolyglotDuke can store encrypted JSON configuration files in the Registry. |
| T1027.016 Junk Code Insertion |
MalwareFatDuke | FatDuke has been packed with junk code and strings. |
| T1033 System Owner/User Discovery |
MalwareLiteDuke | LiteDuke can enumerate the account name on a targeted system. |
| T1036.012 Browser Fingerprint |
MalwareFatDuke | FatDuke has attempted to mimic a compromised user's traffic by using the same user agent as the installed browser. |
| T1057 Process Discovery |
MalwareFatDuke | FatDuke can list running processes on the localhost. |
| T1059.001 PowerShell |
MalwareFatDuke | FatDuke has the ability to execute PowerShell scripts. |
| T1059.001 PowerShell |
MalwareRegDuke | RegDuke can extract and execute PowerShell scripts from C2 communications. |
| T1070.004 File Deletion |
MalwareFatDuke | FatDuke can secure delete its DLL. |
| T1070.004 File Deletion |
MalwareLiteDuke | LiteDuke can securely delete files by first writing random data to the file. |
| T1071.001 Web Protocols |
MalwareMiniDuke | MiniDuke uses HTTP and HTTPS for command and control. |
| T1071.001 Web Protocols |
MalwareLiteDuke | LiteDuke can use HTTP GET requests in C2 communications. |
| T1071.001 Web Protocols |
MalwareFatDuke | FatDuke can be controlled via a custom C2 protocol over HTTP. |
| T1071.001 Web Protocols |
MalwarePolyglotDuke | PolyglotDuke has has used HTTP GET requests in C2 communications. |
| T1078.002 Domain Accounts |
CampaignOperation Ghost | For Operation Ghost, APT29 used stolen administrator credentials for lateral movement on compromised networks. |
| T1082 System Information Discovery |
MalwareFatDuke | FatDuke can collect the user name, Windows version, computer name, and available space on discs from a compromised host. |
| T1082 System Information Discovery |
MalwareMiniDuke | MiniDuke can gather the hostname on a compromised machine. |
| T1082 System Information Discovery |
MalwareLiteDuke | LiteDuke can enumerate the CPUID and BIOS version on a compromised system. |
| T1083 File and Directory Discovery |
MalwareMiniDuke | MiniDuke can enumerate local drives. |
| T1083 File and Directory Discovery |
MalwareFatDuke | FatDuke can enumerate directories on target machines. |
| T1090.001 Internal Proxy |
MalwareFatDuke | FatDuke can used pipes to connect machines with restricted internet access to remote machines via other infected hosts. |
| T1090.001 Internal Proxy |
MalwareMiniDuke | MiniDuke can can use a named pipe to forward communications from one compromised machine with internet access to other compromised machines. |
| T1102.001 Dead Drop Resolver |
MalwarePolyglotDuke | PolyglotDuke can use Twitter, Reddit, Imgur and other websites to get a C2 URL. |
| T1102.001 Dead Drop Resolver |
MalwareMiniDuke | Some MiniDuke components use Twitter to initially obtain the address of a C2 server or as a backup if no hard-coded C2 server responds. |
| T1102.002 Bidirectional Communication |
MalwareRegDuke | RegDuke can use Dropbox as its C2 server. |
| T1102.002 Bidirectional Communication |
CampaignOperation Ghost | For Operation Ghost, APT29 used social media platforms to hide communications to C2 servers. |
| T1105 Ingress Tool Transfer |
MalwareLiteDuke | LiteDuke has the ability to download files. |
| T1105 Ingress Tool Transfer |
MalwareRegDuke | RegDuke can download files from C2. |
| T1105 Ingress Tool Transfer |
MalwareMiniDuke | MiniDuke can download additional encrypted backdoors onto the victim via GIF files. |
| T1105 Ingress Tool Transfer |
MalwarePolyglotDuke | PolyglotDuke can retrieve payloads from the C2 server. |
| T1106 Native API |
MalwareFatDuke | FatDuke can call |
| T1106 Native API |
MalwarePolyglotDuke | PolyglotDuke can use |
| T1112 Modify Registry |
MalwareRegDuke | RegDuke can create seemingly legitimate Registry key to store its encryption key. |
Showing the first 50.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.