Smith, L., Leathery, J., Read, B. (2021, March 4). New SUNSHUTTLE Second-Stage Backdoor Uncovered Targeting U.S.-Based Entity; Possible Connection to UNC2452. Retrieved March 12, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.002 Software Packing |
MalwareGoldMax | GoldMax has been packed for obfuscation. |
| T1027.013 Encrypted/Encoded File |
MalwareGoldMax | GoldMax has written AES-encrypted and Base64-encoded configuration files to disk. |
| T1041 Exfiltration Over C2 Channel |
MalwareGoldMax | GoldMax can exfiltrate files over the existing C2 channel. |
| T1059.003 Windows Command Shell |
MalwareGoldMax | GoldMax can spawn a command shell, and execute native commands. |
| T1071.001 Web Protocols |
MalwareGoldMax | GoldMax has used HTTPS and HTTP GET requests with custom HTTP cookies for C2. |
| T1105 Ingress Tool Transfer |
MalwareGoldMax | GoldMax can download and execute additional files. |
| T1124 System Time Discovery |
MalwareGoldMax | GoldMax can check the current date-time value of the compromised system, comparing it to the hardcoded execution trigger and can send the current timestamp to the C2 server. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareGoldMax | GoldMax has decoded and decrypted the configuration file when executed. |
| T1497.001 System Checks |
MalwareGoldMax | GoldMax will check if it is being run in a virtualized environment by comparing the collected MAC address to |
| T1583.001 Domains |
CampaignSolarWinds Compromise | For the SolarWinds Compromise, APT29 acquired C2 domains, sometimes through resellers. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.