ATT&CKReferencesKaspersky Cloud Atlas August 2019

Kaspersky Cloud Atlas August 2019

GReAT. (2019, August 12). Recent Cloud Atlas activity. Retrieved May 8, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software2

Campaigns0

None recorded.

Procedure examples17

TechniqueUsed byProcedure example
T1005
Data from Local System
GroupInception

Inception used a file hunting plugin to collect .txt, .pdf, .xls or .doc files from the infected host.

T1016
System Network Configuration Discovery
MalwarePowerShower

PowerShower has the ability to identify the current Windows domain of the infected host.

T1033
System Owner/User Discovery
MalwarePowerShower

PowerShower has the ability to identify the current user on the infected host.

T1041
Exfiltration Over C2 Channel
MalwarePowerShower

PowerShower has used a PowerShell document stealer module to pack and exfiltrate .txt, .pdf, .xls or .doc files smaller than 5MB that were modified during the past two days.

T1057
Process Discovery
MalwarePowerShower

PowerShower has the ability to deploy a reconnaissance module to retrieve a list of the active processes.

T1059.005
Visual Basic
MalwareVBShower

VBShower has the ability to execute VBScript files.

T1070.004
File Deletion
MalwareVBShower

VBShower has attempted to complicate forensic analysis by deleting all the files contained in %APPDATA%\..\Local\Temporary Internet Files\Content.Word and %APPDATA%\..\Local Settings\Temporary Internet Files\Content.Word\.

T1071.001
Web Protocols
MalwareVBShower

VBShower has attempted to obtain a VBS script from command and control (C2) nodes over HTTP.

T1105
Ingress Tool Transfer
MalwareVBShower

VBShower has the ability to download VBS files to the target computer.

T1132.001
Standard Encoding
MalwarePowerShower

PowerShower has the ability to encode C2 communications with base64 encoding.

T1203
Exploitation for Client Execution
GroupInception

Inception has exploited CVE-2012-0158, CVE-2014-1761, CVE-2017-11882 and CVE-2018-0802 for execution.

T1204.002
Malicious File
GroupInception

Inception lured victims into clicking malicious files for machine reconnaissance and to execute malware.

T1218.005
Mshta
GroupInception

Inception has used malicious HTA files to drop and execute malware.

T1547.001
Registry Run Keys / Startup Folder
MalwareVBShower

VBShower used HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\[a-f0-9A-F]{8} to maintain persistence.

T1560.001
Archive via Utility
MalwarePowerShower

PowerShower has used 7Zip to compress .txt, .pdf, .xls or .doc files prior to exfiltration.

T1566.001
Spearphishing Attachment
GroupInception

Inception has used weaponized documents attached to spearphishing emails for reconnaissance and initial compromise.

T1588.002
Tool
GroupInception

Inception has obtained and used open-source tools such as LaZagne.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.