ATT&CKReferencesESET Telebots June 2017

ESET Telebots June 2017

Cherepanov, A.. (2017, June 30). TeleBots are back: Supply chain attacks against Ukraine. Retrieved June 11, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples7

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupSandworm Team

Sandworm Team has used its plainpwd tool, a modified version of Mimikatz, and comsvcs.dll to dump Windows credentials from system memory.

T1059.005
Visual Basic
GroupSandworm Team

Sandworm Team has created VBScripts to run an SSH server.

T1102.002
Bidirectional Communication
GroupSandworm Team

Sandworm Team has used the Telegram Bot API from Telegram Messenger to send and receive commands to its Python backdoor. Sandworm Team also used legitimate M.E.Doc software update check requests for sending and receiving commands and hosted malicious payloads on putdrive.com.

T1133
External Remote Services
GroupSandworm Team

Sandworm Team has used Dropbear SSH with a hardcoded backdoor password to maintain persistence within the target network. Sandworm Team has also used VPN tunnels established in legitimate software company infrastructure to gain access to internal networks of that software company's users.

T1195.002
Compromise Software Supply Chain
GroupSandworm Team

Sandworm Team has distributed NotPetya by compromising the legitimate Ukrainian accounting software M.E.Doc and replacing a legitimate software update with a malicious one.

T1485
Data Destruction
GroupSandworm Team

Sandworm Team has used CaddyWiper, SDelete, and the BlackEnergy KillDisk component to overwrite files on victim systems. Additionally, Sandworm Team has used the JUNKMAIL tool to overwrite files with null bytes.

T1561.002
Disk Structure Wipe
GroupSandworm Team

Sandworm Team has used the BlackEnergy KillDisk component to corrupt the infected system's master boot record.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.