ATT&CKReferencesMcAfee Sharpshooter December 2018

McAfee Sharpshooter December 2018

Sherstobitoff, R., Malhotra, A., et. al.. (2018, December 18). Operation Sharpshooter Campaign Targets Global Defense, Critical Infrastructure. Retrieved May 14, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns1

Procedure examples29

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareRising Sun

Rising Sun has collected data and files from a compromised host.

T1012
Query Registry
MalwareRising Sun

Rising Sun has identified the OS product name from a compromised host by searching the registry for `SOFTWARE\MICROSOFT\Windows NT\ CurrentVersion | ProductName`.

T1016
System Network Configuration Discovery
MalwareRising Sun

Rising Sun can detect network adapter and IP address information.

T1016.001
Internet Connection Discovery
MalwareRising Sun

Rising Sun can test a connection to a specified network IP address over a specified port number.

T1027.013
Encrypted/Encoded File
MalwareRising Sun

Configuration data used by Rising Sun has been encrypted using an RC4 stream algorithm.

T1033
System Owner/User Discovery
MalwareRising Sun

Rising Sun can detect the username of the infected host.

T1036.005
Match Legitimate Resource Name or Location
CampaignOperation Sharpshooter

During Operation Sharpshooter, threat actors installed Rising Sun in the Startup folder and disguised it as `mssync.exe`.

T1041
Exfiltration Over C2 Channel
MalwareRising Sun

Rising Sun can send data gathered from the infected machine via HTTP POST request to the C2.

T1057
Process Discovery
MalwareRising Sun

Rising Sun can enumerate all running processes and process information on an infected machine.

T1059.003
Windows Command Shell
MalwareRising Sun

Rising Sun has executed commands using `cmd.exe /c “<command> > <%temp%>\AM<random>. tmp” 2>&1`.

T1059.005
Visual Basic
CampaignOperation Sharpshooter

During Operation Sharpshooter, the threat actors used a VBA macro to execute a simple downloader that installed Rising Sun.

T1070
Indicator Removal
MalwareRising Sun

Rising Sun can clear a memory blog in the process by overwriting it with junk bytes.

T1070.004
File Deletion
MalwareRising Sun

Rising Sun can delete files and artifacts it creates.

T1071.001
Web Protocols
MalwareRising Sun

Rising Sun has used HTTP and HTTPS for command and control.

T1082
System Information Discovery
MalwareRising Sun

Rising Sun can detect the computer name and operating system.

T1083
File and Directory Discovery
MalwareRising Sun

Rising Sun can enumerate information about files from the infected system, including file size, attributes, creation time, last access time, and write time. Rising Sun can enumerate the compilation timestamp of Windows executable files.

T1105
Ingress Tool Transfer
CampaignOperation Sharpshooter

During Operation Sharpshooter, additional payloads were downloaded after a target was infected with a first-stage downloader.

T1106
Native API
CampaignOperation Sharpshooter

During Operation Sharpshooter, the first stage downloader resolved various Windows libraries and APIs, including `LoadLibraryA()`, `GetProcAddress()`, and `CreateProcessA()`.

T1106
Native API
MalwareRising Sun

Rising Sun used dynamic API resolutions to various Windows APIs by leveraging `LoadLibrary()` and `GetProcAddress()`.

T1140
Deobfuscate/Decode Files or Information
MalwareRising Sun

Rising Sun has decrypted itself using a single-byte XOR scheme. Additionally, Rising Sun can decrypt its configuration data at runtime.

T1204.002
Malicious File
CampaignOperation Sharpshooter

During Operation Sharpshooter, the threat actors relied on victims executing malicious Microsoft Word or PDF files.

T1547.001
Registry Run Keys / Startup Folder
CampaignOperation Sharpshooter

During Operation Sharpshooter, a first-stage downloader installed Rising Sun to `%Startup%\mssync.exe` on a compromised host.

T1559.002
Dynamic Data Exchange
CampaignOperation Sharpshooter

During Operation Sharpshooter, threat actors sent malicious Word OLE documents to victims.

T1560.003
Archive via Custom Method
MalwareRising Sun

Rising Sun can archive data using RC4 encryption and Base64 encoding prior to exfiltration.

T1564.001
Hidden Files and Directories
MalwareRising Sun

Rising Sun can modify file attributes to hide files.

T1583.006
Web Services
CampaignOperation Sharpshooter

For Operation Sharpshooter, the threat actors used Dropbox to host lure documents and their first-stage downloader.

T1587.001
Malware
CampaignOperation Sharpshooter

For Operation Sharpshooter, the threat actors used the Rising Sun modular backdoor.

T1608.001
Upload Malware
CampaignOperation Sharpshooter

For Operation Sharpshooter, the threat actors staged malicious files on Dropbox and other websites.

T1680
Local Storage Discovery
MalwareRising Sun

Rising Sun can detect drive information, including drive type, total number of bytes on disk, total number of free bytes on disk, and name of a specified volume.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.