Jurčacko, F. (2024, May 15). To the Moon and back(doors): Lunar landing in diplomatic missions. Retrieved June 26, 2024.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1001.002 Steganography |
MalwareLunarWeb | LunarWeb can receive C2 commands hidden in the structure of .jpg and .gif images. |
| T1001.002 Steganography |
MalwareLunarMail | LunarMail can parse IDAT chunks from .png files to look for zlib-compressed and AES encrypted C2 commands. |
| T1016 System Network Configuration Discovery |
MalwareLunarWeb | LunarWeb can use shell commands to discover network adapters and configuration. |
| T1016 System Network Configuration Discovery |
MalwareLunarLoader | LunarLoader can verify the targeted host's DNS name which is then used in the creation of a decyrption key. |
| T1027.013 Encrypted/Encoded File |
MalwareLunarMail | LunarMail has used RC4 and AES to encrypt strings and its exfiltration configuration respectively. |
| T1027.013 Encrypted/Encoded File |
MalwareLunarWeb | The LunarWeb install files have been encrypted with AES-256. |
| T1030 Data Transfer Size Limits |
MalwareLunarWeb | LunarWeb can split exfiltrated data that exceeds 1.33 MB in size into multiple random sized parts between 384 and 512 KB. |
| T1033 System Owner/User Discovery |
MalwareLunarWeb | LunarWeb can collect user information from the targeted host. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupTurla | Turla has named components of LunarWeb to mimic Zabbix agent logs. |
| T1041 Exfiltration Over C2 Channel |
MalwareLunarMail | LunarMail can use email image attachments with embedded data for receiving C2 commands and data exfiltration. |
| T1047 Windows Management Instrumentation |
MalwareLunarWeb | LunarWeb can use WMI queries for discovery on the victim host. |
| T1049 System Network Connections Discovery |
MalwareLunarWeb | LunarWeb can enumerate system network connections. |
| T1057 Process Discovery |
MalwareLunarWeb | LunarWeb has used shell commands to list running processes. |
| T1059.001 PowerShell |
MalwareLunarWeb | LunarWeb has the ability to run shell commands via PowerShell. |
| T1059.003 Windows Command Shell |
MalwareLunarWeb | LunarWeb can run shell commands using a BAT file with a name matching `%TEMP%\<random_9_alnum_chars>.batfile` or through cmd.exe with the `/c` and `/U` option for Unicode output. |
| T1059.005 Visual Basic |
MalwareLunarMail | LunarMail has been installed using a VBA macro. |
| T1069.001 Local Groups |
MalwareLunarWeb | LunarWeb can discover local group memberships. |
| T1070.004 File Deletion |
MalwareLunarMail | LunarMail can delete the previously used staging directory and files on subsequent rounds of exfiltration and replace it with a new one. |
| T1070.004 File Deletion |
MalwareLunarWeb | LunarWeb can self-delete from a compromised host if safety checks of C2 connectivity fail. |
| T1070.008 Clear Mailbox Data |
MalwareLunarMail | LunarMail can set the `PR_DELETE_AFTER_SUBMIT` flag to delete messages sent for data exfiltration. |
| T1071.001 Web Protocols |
MalwareLunarWeb | LunarWeb can use `POST` to send victim identification to C2 and `GET` to retrieve commands. |
| T1071.003 Mail Protocols |
MalwareLunarMail | LunarMail can communicates with C2 using email messages via the Outlook Messaging API (MAPI). |
| T1074.001 Local Data Staging |
MalwareLunarMail | LunarMail can create a directory in `%TEMP%\` to stage data prior to exfilration. |
| T1082 System Information Discovery |
MalwareLunarMail | LunarMail can capture environmental variables on compromised hosts. |
| T1082 System Information Discovery |
MalwareLunarWeb | LunarWeb can use WMI queries and shell commands such as systeminfo.exe to collect the operating system, BIOS version, and domain name of the targeted system. |
| T1083 File and Directory Discovery |
MalwareLunarMail | LunarMail can search its staging directory for output files it has produced. |
| T1083 File and Directory Discovery |
MalwareLunarWeb | LunarWeb has the ability to retrieve directory listings. |
| T1090 Proxy |
MalwareLunarWeb | LunarWeb has the ability to use a HTTP proxy server for C&C communications. |
| T1095 Non-Application Layer Protocol |
MalwareLunarMail | LunarMail can ping a specific C2 URL with the ID of a victim machine in the subdomain. |
| T1104 Multi-Stage Channels |
MalwareLunarWeb | LunarWeb can use one C2 URL for first contact and to upload information about the host computer and two additional C2 URLs for getting commands. |
| T1113 Screen Capture |
MalwareLunarMail | LunarMail can capture screenshots from compromised hosts. |
| T1114.001 Local Email Collection |
MalwareLunarMail | LunarMail can capture the recipients of sent email messages from compromised accounts. |
| T1132.001 Standard Encoding |
MalwareLunarWeb | LunarWeb can use Base64 encoding to obfuscate C2 commands. |
| T1135 Network Share Discovery |
MalwareLunarWeb | LunarWeb can identify shared resources in compromised environments. |
| T1137.006 Add-ins |
MalwareLunarMail | LunarMail has the ability to use Outlook add-ins for persistence. |
| T1137.006 Add-ins |
MalwareLunarLoader | LunarLoader has the ability to use Microsoft Outlook add-ins to establish persistence. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareLunarLoader | LunarLoader can deobfuscate files containing the next stages in the infection chain. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareLunarWeb | LunarWeb can decrypt strings related to communication configuration using RC4 with a static key. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareLunarMail | LunarMail can decrypt strings to retrieve configuration settings. |
| T1204.002 Malicious File |
MalwareLunarMail | LunarMail has been installed through a malicious macro in a Microsoft Word document. |
| T1480 Execution Guardrails |
MalwareLunarLoader | LunarLoader can use the DNS domain name of a compromised host to create a decryption key to ensure a malicious payload can only execute against the intended targets. |
| T1497.003 Time Based Checks |
MalwareLunarWeb | LunarWeb can pause for a number of hours before entering its C2 communication loop. |
| T1518 Software Discovery |
MalwareLunarWeb | LunarWeb can list installed software on compromised systems. |
| T1518.001 Security Software Discovery |
MalwareLunarWeb | LunarWeb has run shell commands to obtain a list of installed security products. |
| T1543 Create or Modify System Process |
MalwareLunarMail | LunarMail can create an arbitrary process with a specified command line and redirect its output to a staging directory. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupTurla | A Turla Javascript backdoor added a local_update_check value under the Registry key |
| T1559 Inter-Process Communication |
MalwareLunarWeb | LunarWeb can retrieve output from arbitrary processes and shell commands via a pipe. |
| T1560.001 Archive via Utility |
MalwareLunarWeb | LunarWeb can create a ZIP archive with specified files and directories. |
| T1560.002 Archive via Library |
MalwareLunarWeb | LunarWeb can zlib-compress data prior to exfiltration. |
| T1564.012 File/Path Exclusions |
GroupTurla | Turla has placed LunarWeb install files into directories that are excluded from scanning. |
Showing the first 50.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.