ATT&CKReferencesMandiant ROADSWEEP August 2022

Mandiant ROADSWEEP August 2022

Jenkins, L. at al. (2022, August 4). ROADSWEEP Ransomware - Likely Iranian Threat Actor Conducts Politically Motivated Disruptive Activity Against Albanian Government Organizations. Retrieved August 6, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software3

Campaigns1

Procedure examples50

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can collect files from compromised hosts.

T1027
Obfuscated Files or Information
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can use a custom Base64 alphabet to encode an API decryption key.

T1027.001
Binary Padding
MalwareCHIMNEYSWEEP

The CHIMNEYSWEEP installer has been padded with null bytes to inflate its size.

T1027.007
Dynamic API Resolution
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can use `LoadLibrary` and `GetProcAddress` to resolve Windows API function strings at run time.

T1027.009
Embedded Payloads
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can extract RC4 encrypted embedded payloads for privilege escalation.

T1027.013
Encrypted/Encoded File
MalwareROADSWEEP

The ROADSWEEP binary contains RC4 encrypted embedded scripts.

T1033
System Owner/User Discovery
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP has included the victim's computer name and username in C2 messages sent to actor-owned infrastructure.

T1036.005
Match Legitimate Resource Name or Location
CampaignHomeLand Justice

During HomeLand Justice, threat actors renamed ROADSWEEP to GoXML.exe and ZeroCleare to cl.exe.

T1041
Exfiltration Over C2 Channel
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can upload collected files to the command-and-control server.

T1053.005
Scheduled Task
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can use the Windows `SilentCleanup` scheduled task to enable payload execution.

T1056.001
Keylogging
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP has the ability to support keylogging.

T1057
Process Discovery
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can check if a process name contains “creensaver.”

T1059
Command and Scripting Interpreter
MalwareZeroCleare

ZeroCleare can receive command line arguments from an operator to corrupt the file system using the RawDisk driver.

T1059.001
PowerShell
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can invoke the PowerShell command `[Reflection.Assembly]::LoadFile(\"%s\")\n$i=\"\"\n$r=[%s]::%s(\"%s\",[ref] $i)\necho $r,$i\n` to execute secondary payloads.

T1059.003
Windows Command Shell
MalwareROADSWEEP

ROADSWEEP can open cmd.exe to enable command execution.

T1059.005
Visual Basic
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP has executed a script named cln.vbs on compromised hosts.

T1070.004
File Deletion
MalwareZeroCleare

ZeroCleare has the ability to uninstall the RawDisk driver and delete the `rwdsk` file on disk.

T1070.004
File Deletion
MalwareROADSWEEP

ROADSWEEP can use embedded scripts to remove itself from the infected host.

T1070.006
Timestomp
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can time stomp its executable, previously dating it between 2010 to 2021.

T1071.001
Web Protocols
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can send `HTTP GET` requests to  C2.

T1074.001
Local Data Staging
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can store captured screenshots to disk including to a covert store named `APPX.%x%x%x%x%x.tmp` where `%x` is a random value.

T1083
File and Directory Discovery
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP has the ability to enumerate directories for files that match a set list.

T1083
File and Directory Discovery
MalwareROADSWEEP

ROADSWEEP can enumerate files on infected devices and avoid encrypting files with .exe, .dll, .sys, .lnk, or . lck extensions.

T1102
Web Service
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP has the ability to use use Telegram channels to return a list of commands to be executed, to download additional payloads, or to create a reverse shell.

T1105
Ingress Tool Transfer
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can download additional files from C2.

T1106
Native API
MalwareZeroCleare

ZeroCleare can call the `GetSystemDirectoryW` API to locate the system directory.

T1106
Native API
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can use Windows APIs including `LoadLibrary` and `GetProcAddress`.

T1112
Modify Registry
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can use the Windows Registry Environment key to change the `%windir%` variable to point to `c:\Windows` to enable payload execution.

T1113
Screen Capture
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can capture screenshots on targeted systems using a timer and either upload them or store them to disk.

T1115
Clipboard Data
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can capture content from the clipboard.

T1120
Peripheral Device Discovery
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can monitor for removable drives.

T1120
Peripheral Device Discovery
MalwareROADSWEEP

ROADSWEEP can identify removable drives attached to the victim's machine.

T1132.002
Non-Standard Encoding
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can use a custom Base64 alphabet for encoding C2.

T1140
Deobfuscate/Decode Files or Information
MalwareROADSWEEP

ROADSWEEP can decrypt embedded scripts prior to execution.

T1140
Deobfuscate/Decode Files or Information
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can use an embedded RC4 key to decrypt Windows API function strings.

T1218.003
CMSTP
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can use CMSTP.exe to install a malicious Microsoft Connection Manager Profile.

T1480
Execution Guardrails
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can execute a task which leads to execution if it finds a process name containing “creensaver.”

T1480
Execution Guardrails
MalwareROADSWEEP

ROADSWEEP requires four command line arguments to execute correctly, otherwise it will produce a message box and halt execution.

T1486
Data Encrypted for Impact
MalwareROADSWEEP

ROADSWEEP can RC4 encrypt content in blocks on targeted systems.

T1486
Data Encrypted for Impact
CampaignHomeLand Justice

During HomeLand Justice, threat actors used ROADSWEEP ransomware to encrypt files on targeted systems.

T1489
Service Stop
MalwareROADSWEEP

ROADSWEEP can disable critical services and processes.

T1490
Inhibit System Recovery
MalwareROADSWEEP

ROADSWEEP has the ability to disable `SystemRestore` and Volume Shadow Copies.

T1518.001
Security Software Discovery
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP is capable of checking whether a compromised device is running DeepFreeze by Faronics.

T1529
System Shutdown/Reboot
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can reboot or shutdown the targeted system or logoff the current user.

T1548.002
Bypass User Account Control
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can make use of the Windows `SilentCleanup` scheduled task to execute its payload with elevated privileges.

T1553.002
Code Signing
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP has been dropped by a self-extracting archive signed with a valid digital certificate.

T1559
Inter-Process Communication
MalwareROADSWEEP

ROADSWEEP can pipe command output to a targeted process.

T1561.002
Disk Structure Wipe
MalwareZeroCleare

ZeroCleare can corrupt the file system and wipe the system drive on targeted hosts.

T1680
Local Storage Discovery
MalwareZeroCleare

ZeroCleare can use the `IOCTL_DISK_GET_DRIVE_GEOMETRY_EX`, `IOCTL_DISK_GET_DRIVE_GEOMETRY`, and `IOCTL_DISK_GET_LENGTH_INFO` system calls to compute disk size.

T1680
Local Storage Discovery
MalwareROADSWEEP

ROADSWEEP can enumerate logical drives on targeted devices.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.