ATT&CKReferencesESET Dukes October 2019

ESET Dukes October 2019

Faou, M., Tartare, M., Dupuy, T. (2019, October). OPERATION GHOST. Retrieved September 23, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software4

Campaigns1

Procedure examples71

TechniqueUsed byProcedure example
T1001.002
Steganography
CampaignOperation Ghost

During Operation Ghost, APT29 used steganography to hide the communications between the implants and their C&C servers.

T1005
Data from Local System
MalwareFatDuke

FatDuke can copy files and directories from a compromised host.

T1008
Fallback Channels
MalwareFatDuke

FatDuke has used several C2 servers per targeted organization.

T1012
Query Registry
MalwareFatDuke

FatDuke can get user agent strings for the default browser from HKCU\Software\Classes\http\shell\open\command.

T1012
Query Registry
MalwareLiteDuke

LiteDuke can query the Registry to check for the presence of HKCU\Software\KasperskyLab.

T1016
System Network Configuration Discovery
MalwareLiteDuke

LiteDuke has the ability to discover the proxy configuration of Firefox and/or Opera.

T1016
System Network Configuration Discovery
MalwareFatDuke

FatDuke can identify the MAC address on the target computer.

T1027
Obfuscated Files or Information
MalwareMiniDuke

MiniDuke can use control flow flattening to obscure code.

T1027
Obfuscated Files or Information
MalwareFatDuke

FatDuke can use base64 encoding, string stacking, and opaque predicates for obfuscation.

T1027
Obfuscated Files or Information
MalwarePolyglotDuke

PolyglotDuke can custom encrypt strings.

T1027
Obfuscated Files or Information
MalwareRegDuke

RegDuke can use control-flow flattening or the commercially available .NET Reactor for obfuscation.

T1027.002
Software Packing
MalwareLiteDuke

LiteDuke has been packed with multiple layers of encryption.

T1027.002
Software Packing
MalwareFatDuke

FatDuke has been regularly repacked by its operators to create large binaries and evade detection.

T1027.003
Steganography
MalwareLiteDuke

LiteDuke has used image files to hide its loader component.

T1027.003
Steganography
MalwarePolyglotDuke

PolyglotDuke can use steganography to hide C2 information in images.

T1027.003
Steganography
CampaignOperation Ghost

During Operation Ghost, APT29 used steganography to hide payloads inside valid images.

T1027.003
Steganography
MalwareRegDuke

RegDuke can hide data in images, including use of the Least Significant Bit (LSB).

T1027.011
Fileless Storage
MalwareRegDuke

RegDuke can store its encryption key in the Registry.

T1027.011
Fileless Storage
MalwarePolyglotDuke

PolyglotDuke can store encrypted JSON configuration files in the Registry.

T1027.016
Junk Code Insertion
MalwareFatDuke

FatDuke has been packed with junk code and strings.

T1033
System Owner/User Discovery
MalwareLiteDuke

LiteDuke can enumerate the account name on a targeted system.

T1036.012
Browser Fingerprint
MalwareFatDuke

FatDuke has attempted to mimic a compromised user's traffic by using the same user agent as the installed browser.

T1057
Process Discovery
MalwareFatDuke

FatDuke can list running processes on the localhost.

T1059.001
PowerShell
MalwareFatDuke

FatDuke has the ability to execute PowerShell scripts.

T1059.001
PowerShell
MalwareRegDuke

RegDuke can extract and execute PowerShell scripts from C2 communications.

T1070.004
File Deletion
MalwareFatDuke

FatDuke can secure delete its DLL.

T1070.004
File Deletion
MalwareLiteDuke

LiteDuke can securely delete files by first writing random data to the file.

T1071.001
Web Protocols
MalwareMiniDuke

MiniDuke uses HTTP and HTTPS for command and control.

T1071.001
Web Protocols
MalwareLiteDuke

LiteDuke can use HTTP GET requests in C2 communications.

T1071.001
Web Protocols
MalwareFatDuke

FatDuke can be controlled via a custom C2 protocol over HTTP.

T1071.001
Web Protocols
MalwarePolyglotDuke

PolyglotDuke has has used HTTP GET requests in C2 communications.

T1078.002
Domain Accounts
CampaignOperation Ghost

For Operation Ghost, APT29 used stolen administrator credentials for lateral movement on compromised networks.

T1082
System Information Discovery
MalwareFatDuke

FatDuke can collect the user name, Windows version, computer name, and available space on discs from a compromised host.

T1082
System Information Discovery
MalwareMiniDuke

MiniDuke can gather the hostname on a compromised machine.

T1082
System Information Discovery
MalwareLiteDuke

LiteDuke can enumerate the CPUID and BIOS version on a compromised system.

T1083
File and Directory Discovery
MalwareMiniDuke

MiniDuke can enumerate local drives.

T1083
File and Directory Discovery
MalwareFatDuke

FatDuke can enumerate directories on target machines.

T1090.001
Internal Proxy
MalwareFatDuke

FatDuke can used pipes to connect machines with restricted internet access to remote machines via other infected hosts.

T1090.001
Internal Proxy
MalwareMiniDuke

MiniDuke can can use a named pipe to forward communications from one compromised machine with internet access to other compromised machines.

T1102.001
Dead Drop Resolver
MalwarePolyglotDuke

PolyglotDuke can use Twitter, Reddit, Imgur and other websites to get a C2 URL.

T1102.001
Dead Drop Resolver
MalwareMiniDuke

Some MiniDuke components use Twitter to initially obtain the address of a C2 server or as a backup if no hard-coded C2 server responds.

T1102.002
Bidirectional Communication
MalwareRegDuke

RegDuke can use Dropbox as its C2 server.

T1102.002
Bidirectional Communication
CampaignOperation Ghost

For Operation Ghost, APT29 used social media platforms to hide communications to C2 servers.

T1105
Ingress Tool Transfer
MalwareLiteDuke

LiteDuke has the ability to download files.

T1105
Ingress Tool Transfer
MalwareRegDuke

RegDuke can download files from C2.

T1105
Ingress Tool Transfer
MalwareMiniDuke

MiniDuke can download additional encrypted backdoors onto the victim via GIF files.

T1105
Ingress Tool Transfer
MalwarePolyglotDuke

PolyglotDuke can retrieve payloads from the C2 server.

T1106
Native API
MalwareFatDuke

FatDuke can call ShellExecuteW to open the default browser on the URL localhost.

T1106
Native API
MalwarePolyglotDuke

PolyglotDuke can use LoadLibraryW and CreateProcess to load and execute code.

T1112
Modify Registry
MalwareRegDuke

RegDuke can create seemingly legitimate Registry key to store its encryption key.

Showing the first 50.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.