Jenkins, L. at al. (2022, August 4). ROADSWEEP Ransomware - Likely Iranian Threat Actor Conducts Politically Motivated Disruptive Activity Against Albanian Government Organizations. Retrieved August 6, 2024.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can collect files from compromised hosts. |
| T1027 Obfuscated Files or Information |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can use a custom Base64 alphabet to encode an API decryption key. |
| T1027.001 Binary Padding |
MalwareCHIMNEYSWEEP | The CHIMNEYSWEEP installer has been padded with null bytes to inflate its size. |
| T1027.007 Dynamic API Resolution |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can use `LoadLibrary` and `GetProcAddress` to resolve Windows API function strings at run time. |
| T1027.009 Embedded Payloads |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can extract RC4 encrypted embedded payloads for privilege escalation. |
| T1027.013 Encrypted/Encoded File |
MalwareROADSWEEP | The ROADSWEEP binary contains RC4 encrypted embedded scripts. |
| T1033 System Owner/User Discovery |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP has included the victim's computer name and username in C2 messages sent to actor-owned infrastructure. |
| T1036.005 Match Legitimate Resource Name or Location |
CampaignHomeLand Justice | During HomeLand Justice, threat actors renamed ROADSWEEP to GoXML.exe and ZeroCleare to cl.exe. |
| T1041 Exfiltration Over C2 Channel |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can upload collected files to the command-and-control server. |
| T1053.005 Scheduled Task |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can use the Windows `SilentCleanup` scheduled task to enable payload execution. |
| T1056.001 Keylogging |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP has the ability to support keylogging. |
| T1057 Process Discovery |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can check if a process name contains “creensaver.” |
| T1059 Command and Scripting Interpreter |
MalwareZeroCleare | ZeroCleare can receive command line arguments from an operator to corrupt the file system using the RawDisk driver. |
| T1059.001 PowerShell |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can invoke the PowerShell command `[Reflection.Assembly]::LoadFile(\"%s\")\n$i=\"\"\n$r=[%s]::%s(\"%s\",[ref] $i)\necho $r,$i\n` to execute secondary payloads. |
| T1059.003 Windows Command Shell |
MalwareROADSWEEP | ROADSWEEP can open cmd.exe to enable command execution. |
| T1059.005 Visual Basic |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP has executed a script named cln.vbs on compromised hosts. |
| T1070.004 File Deletion |
MalwareZeroCleare | ZeroCleare has the ability to uninstall the RawDisk driver and delete the `rwdsk` file on disk. |
| T1070.004 File Deletion |
MalwareROADSWEEP | ROADSWEEP can use embedded scripts to remove itself from the infected host. |
| T1070.006 Timestomp |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can time stomp its executable, previously dating it between 2010 to 2021. |
| T1071.001 Web Protocols |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can send `HTTP GET` requests to C2. |
| T1074.001 Local Data Staging |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can store captured screenshots to disk including to a covert store named `APPX.%x%x%x%x%x.tmp` where `%x` is a random value. |
| T1083 File and Directory Discovery |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP has the ability to enumerate directories for files that match a set list. |
| T1083 File and Directory Discovery |
MalwareROADSWEEP | ROADSWEEP can enumerate files on infected devices and avoid encrypting files with .exe, .dll, .sys, .lnk, or . lck extensions. |
| T1102 Web Service |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP has the ability to use use Telegram channels to return a list of commands to be executed, to download additional payloads, or to create a reverse shell. |
| T1105 Ingress Tool Transfer |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can download additional files from C2. |
| T1106 Native API |
MalwareZeroCleare | ZeroCleare can call the `GetSystemDirectoryW` API to locate the system directory. |
| T1106 Native API |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can use Windows APIs including `LoadLibrary` and `GetProcAddress`. |
| T1112 Modify Registry |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can use the Windows Registry Environment key to change the `%windir%` variable to point to `c:\Windows` to enable payload execution. |
| T1113 Screen Capture |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can capture screenshots on targeted systems using a timer and either upload them or store them to disk. |
| T1115 Clipboard Data |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can capture content from the clipboard. |
| T1120 Peripheral Device Discovery |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can monitor for removable drives. |
| T1120 Peripheral Device Discovery |
MalwareROADSWEEP | ROADSWEEP can identify removable drives attached to the victim's machine. |
| T1132.002 Non-Standard Encoding |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can use a custom Base64 alphabet for encoding C2. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareROADSWEEP | ROADSWEEP can decrypt embedded scripts prior to execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can use an embedded RC4 key to decrypt Windows API function strings. |
| T1218.003 CMSTP |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can use CMSTP.exe to install a malicious Microsoft Connection Manager Profile. |
| T1480 Execution Guardrails |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can execute a task which leads to execution if it finds a process name containing “creensaver.” |
| T1480 Execution Guardrails |
MalwareROADSWEEP | ROADSWEEP requires four command line arguments to execute correctly, otherwise it will produce a message box and halt execution. |
| T1486 Data Encrypted for Impact |
MalwareROADSWEEP | ROADSWEEP can RC4 encrypt content in blocks on targeted systems. |
| T1486 Data Encrypted for Impact |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used ROADSWEEP ransomware to encrypt files on targeted systems. |
| T1489 Service Stop |
MalwareROADSWEEP | ROADSWEEP can disable critical services and processes. |
| T1490 Inhibit System Recovery |
MalwareROADSWEEP | ROADSWEEP has the ability to disable `SystemRestore` and Volume Shadow Copies. |
| T1518.001 Security Software Discovery |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP is capable of checking whether a compromised device is running DeepFreeze by Faronics. |
| T1529 System Shutdown/Reboot |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can reboot or shutdown the targeted system or logoff the current user. |
| T1548.002 Bypass User Account Control |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can make use of the Windows `SilentCleanup` scheduled task to execute its payload with elevated privileges. |
| T1553.002 Code Signing |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP has been dropped by a self-extracting archive signed with a valid digital certificate. |
| T1559 Inter-Process Communication |
MalwareROADSWEEP | ROADSWEEP can pipe command output to a targeted process. |
| T1561.002 Disk Structure Wipe |
MalwareZeroCleare | ZeroCleare can corrupt the file system and wipe the system drive on targeted hosts. |
| T1680 Local Storage Discovery |
MalwareZeroCleare | ZeroCleare can use the `IOCTL_DISK_GET_DRIVE_GEOMETRY_EX`, `IOCTL_DISK_GET_DRIVE_GEOMETRY`, and `IOCTL_DISK_GET_LENGTH_INFO` system calls to compute disk size. |
| T1680 Local Storage Discovery |
MalwareROADSWEEP | ROADSWEEP can enumerate logical drives on targeted devices. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.