ATT&CKReferencesANSSI Sandworm January 2021

ANSSI Sandworm January 2021

ANSSI. (2021, January 27). SANDWORM INTRUSION SET CAMPAIGN TARGETING CENTREON SYSTEMS. Retrieved March 30, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples29

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareP.A.S. Webshell

P.A.S. Webshell has the ability to copy files on a compromised host.

T1008
Fallback Channels
MalwareExaramel for Linux

Exaramel for Linux can attempt to find a new C2 server if it receives an error.

T1027
Obfuscated Files or Information
MalwareP.A.S. Webshell

P.A.S. Webshell can use encryption and base64 encoding to hide strings and to enforce access control once deployed.

T1027.013
Encrypted/Encoded File
MalwareExaramel for Linux

Exaramel for Linux uses RC4 for encrypting the configuration.

T1033
System Owner/User Discovery
MalwareExaramel for Linux

Exaramel for Linux can run whoami to identify the system owner.

T1046
Network Service Discovery
MalwareP.A.S. Webshell

P.A.S. Webshell can scan networks for open ports and listening services.

T1053.003
Cron
MalwareExaramel for Linux

Exaramel for Linux uses crontab for persistence if it does not have root privileges.

T1059
Command and Scripting Interpreter
MalwareP.A.S. Webshell

P.A.S. Webshell has the ability to create reverse shells with Perl scripts.

T1059.004
Unix Shell
MalwareExaramel for Linux

Exaramel for Linux has a command to execute a shell command on the system.

T1070.004
File Deletion
MalwareExaramel for Linux

Exaramel for Linux can uninstall its persistence mechanism and delete its configuration file.

T1070.004
File Deletion
MalwareP.A.S. Webshell

P.A.S. Webshell can delete scripts from a subdirectory of /tmp after they are run.

T1071.001
Web Protocols
MalwareP.A.S. Webshell

P.A.S. Webshell can issue commands via HTTP POST.

T1071.001
Web Protocols
MalwareExaramel for Linux

Exaramel for Linux uses HTTPS for C2 communications.

T1083
File and Directory Discovery
MalwareP.A.S. Webshell

P.A.S. Webshell has the ability to list files and file characteristics including extension, size, ownership, and permissions.

T1087.001
Local Account
MalwareP.A.S. Webshell

P.A.S. Webshell can display the /etc/passwd file on a compromised host.

T1105
Ingress Tool Transfer
MalwareP.A.S. Webshell

P.A.S. Webshell can upload and download files to and from compromised hosts.

T1105
Ingress Tool Transfer
MalwareExaramel for Linux

Exaramel for Linux has a command to download a file from and to a remote C2 server.

T1110.001
Password Guessing
MalwareP.A.S. Webshell

P.A.S. Webshell can use predefined users and passwords to execute brute force attacks against SSH, FTP, POP3, MySQL, MSSQL, and PostgreSQL services.

T1133
External Remote Services
GroupSandworm Team

Sandworm Team has used Dropbear SSH with a hardcoded backdoor password to maintain persistence within the target network. Sandworm Team has also used VPN tunnels established in legitimate software company infrastructure to gain access to internal networks of that software company's users.

T1140
Deobfuscate/Decode Files or Information
MalwareExaramel for Linux

Exaramel for Linux can decrypt its configuration file.

T1140
Deobfuscate/Decode Files or Information
MalwareP.A.S. Webshell

P.A.S. Webshell can use a decryption mechanism to process a user supplied password and allow execution.

T1213.006
Databases
MalwareP.A.S. Webshell

P.A.S. Webshell has the ability to list and extract data from SQL databases.

T1222.002
Linux and Mac Permissions
MalwareP.A.S. Webshell

P.A.S. Webshell has the ability to modify file permissions.

T1505.003
Web Shell
MalwareP.A.S. Webshell

P.A.S. Webshell can gain remote access and execution on target web servers.

T1505.003
Web Shell
GroupSandworm Team

Sandworm Team has used webshells including P.A.S. Webshell to maintain access to victim networks.

T1518
Software Discovery
MalwareP.A.S. Webshell

P.A.S. Webshell can list PHP server configuration details.

T1543
Create or Modify System Process
MalwareExaramel for Linux

Exaramel for Linux has a hardcoded location that it uses to achieve persistence if the startup system is Upstart or System V and it is running as root.

T1543.002
Systemd Service
MalwareExaramel for Linux

Exaramel for Linux has a hardcoded location under systemd that it uses to achieve persistence if it is running as root.

T1548.001
Setuid and Setgid
MalwareExaramel for Linux

Exaramel for Linux can execute commands with high privileges via a specific binary with setuid functionality.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.