ATT&CKReferencesUnit42 Emissary Panda May 2019

Unit42 Emissary Panda May 2019

Falcone, R. and Lancaster, T. (2019, May 28). Emissary Panda Attacks Middle East Government Sharepoint Servers. Retrieved July 9, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples17

TechniqueUsed byProcedure example
T1007
System Service Discovery
MalwareHyperBro

HyperBro can list all services and their configurations.

T1027.013
Encrypted/Encoded File
GroupThreat Group-3390

A Threat Group-3390 tool can encrypt payloads using XOR. Threat Group-3390 malware is also obfuscated using Metasploit’s shikata_ga_nai encoder.

T1027.015
Compression
GroupThreat Group-3390

Threat Group-3390 malware is compressed with LZNT1 compression.

T1046
Network Service Discovery
GroupThreat Group-3390

Threat Group-3390 actors use the Hunter tool to conduct network service discovery for vulnerable systems.

T1055
Process Injection
MalwareHyperBro

HyperBro can run shellcode it injects into a newly created process.

T1059.003
Windows Command Shell
GroupThreat Group-3390

Threat Group-3390 has used command-line interfaces for execution.

T1070.004
File Deletion
MalwareHyperBro

HyperBro has the ability to delete a specified file.

T1071.001
Web Protocols
MalwareHyperBro

HyperBro has used HTTPS for C2 communications.

T1105
Ingress Tool Transfer
MalwareHyperBro

HyperBro has the ability to download additional files.

T1106
Native API
MalwareHyperBro

HyperBro has the ability to run an application (CreateProcessW) or script/file (ShellExecuteW) via API.

T1113
Screen Capture
MalwareHyperBro

HyperBro has the ability to take screenshots.

T1210
Exploitation of Remote Services
GroupThreat Group-3390

Threat Group-3390 has exploited MS17-010 to move laterally to other systems on the network.

T1505.003
Web Shell
GroupThreat Group-3390

Threat Group-3390 has used a variety of Web shells.

T1569.002
Service Execution
MalwareHyperBro

HyperBro has the ability to start and stop a specified service.

T1574.001
DLL
MalwareHyperBro

HyperBro has used a legitimate application to sideload a DLL to decrypt, decompress, and run a payload.

T1574.001
DLL
GroupThreat Group-3390

Threat Group-3390 has performed DLL search order hijacking to execute their payload. Threat Group-3390 has also used DLL side-loading, including by using legitimate Kaspersky antivirus variants as well as `rc.exe`, a legitimate Microsoft Resource Compiler.

T1588.002
Tool
GroupThreat Group-3390

Threat Group-3390 has obtained and used tools such as Impacket, pwdump, Mimikatz, gsecdump, NBTscan, and Windows Credential Editor.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.