ATT&CKReferencesRapid7 HAFNIUM Mar 2021

Rapid7 HAFNIUM Mar 2021

Eoin Miller. (2021, March 23). Defending Against the Zero Day: Analyzing Attacker Behavior Post-Exploitation of Microsoft Exchange. Retrieved October 27, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples15

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupHAFNIUM

HAFNIUM has used procdump to dump the LSASS process memory.

T1005
Data from Local System
MalwareChina Chopper

China Chopper's server component can upload local files.

T1005
Data from Local System
GroupHAFNIUM

HAFNIUM has collected data and files from a compromised machine.

T1016
System Network Configuration Discovery
GroupHAFNIUM

HAFNIUM has collected IP information via IPInfo.

T1016.001
Internet Connection Discovery
GroupHAFNIUM

HAFNIUM has checked for network connectivity from a compromised host using `ping`, including attempts to contact `google[.]com`.

T1018
Remote System Discovery
GroupHAFNIUM

HAFNIUM has enumerated domain controllers using `net group "Domain computers"` and `nltest /dclist`.

T1033
System Owner/User Discovery
GroupHAFNIUM

HAFNIUM has used `whoami` to gather user information.

T1057
Process Discovery
GroupHAFNIUM

HAFNIUM has used `tasklist` to enumerate processes.

T1059.003
Windows Command Shell
GroupHAFNIUM

HAFNIUM has used `cmd.exe` to execute commands on the victim's machine.

T1083
File and Directory Discovery
GroupHAFNIUM

HAFNIUM has searched file contents on a compromised host.

T1083
File and Directory Discovery
MalwareChina Chopper

China Chopper's server component can list directory contents.

T1105
Ingress Tool Transfer
GroupHAFNIUM

HAFNIUM has downloaded malware and tools--including Nishang and PowerCat--onto a compromised host.

T1105
Ingress Tool Transfer
MalwareChina Chopper

China Chopper's server component can download remote files.

T1505.003
Web Shell
GroupHAFNIUM

HAFNIUM has deployed multiple web shells on compromised servers including SIMPLESEESHARP, SPORTSBALL, China Chopper, and ASPXSpy.

T1564.001
Hidden Files and Directories
GroupHAFNIUM

HAFNIUM has hidden files on a compromised host.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.