ATT&CKReferencesMandiant UNC3890 Aug 2022

Mandiant UNC3890 Aug 2022

Mandiant Israel Research Team. (2022, August 17). Suspected Iranian Actor Targeting Israeli Shipping, Healthcare, Government and Energy Sectors. Retrieved September 21, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software2

Campaigns1

Procedure examples27

TechniqueUsed byProcedure example
T1016.001
Internet Connection Discovery
MalwareSUGARUSH

SUGARUSH has checked for internet connectivity from an infected host before attempting to establish a new TCP connection.

T1036.004
Masquerade Task or Service
MalwareSUGARDUMP

SUGARDUMP's scheduled task has been named `MicrosoftInternetExplorerCrashRepoeterTaskMachineUA` or `MicrosoftEdgeCrashRepoeterTaskMachineUA`, depending on the Windows OS version.

T1036.005
Match Legitimate Resource Name or Location
MalwareSUGARDUMP

SUGARDUMP has been named `CrashReporter.exe` to appear as a legitimate Mozilla executable.

T1041
Exfiltration Over C2 Channel
MalwareSUGARDUMP

SUGARDUMP has sent stolen credentials and other data to its C2 server.

T1053.005
Scheduled Task
MalwareSUGARDUMP

SUGARDUMP has created scheduled tasks called `MicrosoftInternetExplorerCrashRepoeterTaskMachineUA` and `MicrosoftEdgeCrashRepoeterTaskMachineUA`, which were configured to execute `CrashReporter.exe` during user logon.

T1059.003
Windows Command Shell
MalwareSUGARUSH

SUGARUSH has used `cmd` for execution on an infected host.

T1071.001
Web Protocols
MalwareSUGARDUMP

A SUGARDUMP variant has used HTTP for C2.

T1071.003
Mail Protocols
MalwareSUGARDUMP

A SUGARDUMP variant used SMTP for C2.

T1074.001
Local Data Staging
MalwareSUGARDUMP

SUGARDUMP has stored collected data under `%<malware_execution_folder>%\\CrashLog.txt`.

T1083
File and Directory Discovery
MalwareSUGARDUMP

SUGARDUMP can search for and collect data from specific Chrome, Opera, Microsoft Edge, and Firefox files, including any folders that have the string `Profile` in its name.

T1095
Non-Application Layer Protocol
MalwareSUGARUSH

SUGARUSH has used TCP for C2.

T1105
Ingress Tool Transfer
CampaignC0010

During C0010, UNC3890 actors downloaded tools and malware onto a compromised host.

T1189
Drive-by Compromise
CampaignC0010

During C0010, UNC3890 actors likely established a watering hole that was hosted on a login page of a legitimate Israeli shipping company that was active until at least November 2021.

T1204.002
Malicious File
MalwareSUGARDUMP

Some SUGARDUMP variants required a user to enable a macro within a malicious .xls file for execution.

T1217
Browser Information Discovery
MalwareSUGARDUMP

SUGARDUMP has collected browser bookmark and history information.

T1518
Software Discovery
MalwareSUGARDUMP

SUGARDUMP can identify Chrome, Opera, Edge Chromium, and Firefox browsers, including version number, on a compromised host.

T1543.003
Windows Service
MalwareSUGARUSH

SUGARUSH has created a service named `Service1` for persistence.

T1555.003
Credentials from Web Browsers
MalwareSUGARDUMP

SUGARDUMP variants have harvested credentials from browsers such as Firefox, Chrome, Opera, and Edge.

T1560.003
Archive via Custom Method
MalwareSUGARDUMP

SUGARDUMP has encrypted collected data using AES CBC mode and encoded it using Base64.

T1571
Non-Standard Port
MalwareSUGARUSH

SUGARUSH has used port 4585 for a TCP connection to its C2.

T1583.001
Domains
CampaignC0010

For C0010, UNC3890 actors established domains that appeared to be legitimate services and entities, such as LinkedIn, Facebook, Office 365, and Pfizer.

T1584.001
Domains
CampaignC0010

During C0010, UNC3890 actors likely compromised the domain of a legitimate Israeli shipping company.

T1587.001
Malware
CampaignC0010

For C0010, UNC3890 actors used unique malware, including SUGARUSH and SUGARDUMP.

T1588.002
Tool
CampaignC0010

For C0010, UNC3890 actors obtained multiple publicly-available tools, including METASPLOIT, UNICORN, and NorthStar C2.

T1608.001
Upload Malware
CampaignC0010

For C0010, UNC3890 actors staged malware on their infrastructure for direct download onto a compromised system.

T1608.002
Upload Tool
CampaignC0010

For C0010, UNC3890 actors staged tools on their infrastructure to download directly onto a compromised system.

T1608.004
Drive-by Target
CampaignC0010

For C0010, the threat actors compromised the login page of a legitimate Israeli shipping company and likely established a watering hole that collected visitor information.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.