Mandiant Israel Research Team. (2022, August 17). Suspected Iranian Actor Targeting Israeli Shipping, Healthcare, Government and Energy Sectors. Retrieved September 21, 2022.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016.001 Internet Connection Discovery |
MalwareSUGARUSH | SUGARUSH has checked for internet connectivity from an infected host before attempting to establish a new TCP connection. |
| T1036.004 Masquerade Task or Service |
MalwareSUGARDUMP | SUGARDUMP's scheduled task has been named `MicrosoftInternetExplorerCrashRepoeterTaskMachineUA` or `MicrosoftEdgeCrashRepoeterTaskMachineUA`, depending on the Windows OS version. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareSUGARDUMP | SUGARDUMP has been named `CrashReporter.exe` to appear as a legitimate Mozilla executable. |
| T1041 Exfiltration Over C2 Channel |
MalwareSUGARDUMP | SUGARDUMP has sent stolen credentials and other data to its C2 server. |
| T1053.005 Scheduled Task |
MalwareSUGARDUMP | SUGARDUMP has created scheduled tasks called `MicrosoftInternetExplorerCrashRepoeterTaskMachineUA` and `MicrosoftEdgeCrashRepoeterTaskMachineUA`, which were configured to execute `CrashReporter.exe` during user logon. |
| T1059.003 Windows Command Shell |
MalwareSUGARUSH | SUGARUSH has used `cmd` for execution on an infected host. |
| T1071.001 Web Protocols |
MalwareSUGARDUMP | A SUGARDUMP variant has used HTTP for C2. |
| T1071.003 Mail Protocols |
MalwareSUGARDUMP | A SUGARDUMP variant used SMTP for C2. |
| T1074.001 Local Data Staging |
MalwareSUGARDUMP | SUGARDUMP has stored collected data under `%<malware_execution_folder>%\\CrashLog.txt`. |
| T1083 File and Directory Discovery |
MalwareSUGARDUMP | SUGARDUMP can search for and collect data from specific Chrome, Opera, Microsoft Edge, and Firefox files, including any folders that have the string `Profile` in its name. |
| T1095 Non-Application Layer Protocol |
MalwareSUGARUSH | SUGARUSH has used TCP for C2. |
| T1105 Ingress Tool Transfer |
CampaignC0010 | During C0010, UNC3890 actors downloaded tools and malware onto a compromised host. |
| T1189 Drive-by Compromise |
CampaignC0010 | During C0010, UNC3890 actors likely established a watering hole that was hosted on a login page of a legitimate Israeli shipping company that was active until at least November 2021. |
| T1204.002 Malicious File |
MalwareSUGARDUMP | Some SUGARDUMP variants required a user to enable a macro within a malicious .xls file for execution. |
| T1217 Browser Information Discovery |
MalwareSUGARDUMP | SUGARDUMP has collected browser bookmark and history information. |
| T1518 Software Discovery |
MalwareSUGARDUMP | SUGARDUMP can identify Chrome, Opera, Edge Chromium, and Firefox browsers, including version number, on a compromised host. |
| T1543.003 Windows Service |
MalwareSUGARUSH | SUGARUSH has created a service named `Service1` for persistence. |
| T1555.003 Credentials from Web Browsers |
MalwareSUGARDUMP | SUGARDUMP variants have harvested credentials from browsers such as Firefox, Chrome, Opera, and Edge. |
| T1560.003 Archive via Custom Method |
MalwareSUGARDUMP | SUGARDUMP has encrypted collected data using AES CBC mode and encoded it using Base64. |
| T1571 Non-Standard Port |
MalwareSUGARUSH | SUGARUSH has used port 4585 for a TCP connection to its C2. |
| T1583.001 Domains |
CampaignC0010 | For C0010, UNC3890 actors established domains that appeared to be legitimate services and entities, such as LinkedIn, Facebook, Office 365, and Pfizer. |
| T1584.001 Domains |
CampaignC0010 | During C0010, UNC3890 actors likely compromised the domain of a legitimate Israeli shipping company. |
| T1587.001 Malware |
CampaignC0010 | For C0010, UNC3890 actors used unique malware, including SUGARUSH and SUGARDUMP. |
| T1588.002 Tool |
CampaignC0010 | For C0010, UNC3890 actors obtained multiple publicly-available tools, including METASPLOIT, UNICORN, and NorthStar C2. |
| T1608.001 Upload Malware |
CampaignC0010 | For C0010, UNC3890 actors staged malware on their infrastructure for direct download onto a compromised system. |
| T1608.002 Upload Tool |
CampaignC0010 | For C0010, UNC3890 actors staged tools on their infrastructure to download directly onto a compromised system. |
| T1608.004 Drive-by Target |
CampaignC0010 | For C0010, the threat actors compromised the login page of a legitimate Israeli shipping company and likely established a watering hole that collected visitor information. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.