ATT&CKReferencesAccenture Dragonfish Jan 2018

Accenture Dragonfish Jan 2018

Accenture Security. (2018, January 27). DRAGONFISH DELIVERS NEW FORM OF ELISE MALWARE TARGETING ASEAN DEFENCE MINISTERS’ MEETING AND ASSOCIATES. Retrieved November 17, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples8

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareElise

Elise executes ipconfig /all after initial communication is made to the remote server.

T1055.001
Dynamic-link Library Injection
MalwareElise

Elise injects DLL files into iexplore.exe.

T1057
Process Discovery
MalwareElise

Elise enumerates processes via the tasklist command.

T1070.004
File Deletion
MalwareElise

Elise is capable of launching a remote shell on the host to delete itself.

T1074.001
Local Data Staging
MalwareElise

Elise creates a file in AppData\Local\Microsoft\Windows\Explorer and stores all harvested data in that file.

T1083
File and Directory Discovery
MalwareElise

A variant of Elise executes dir C:\progra~1 when initially run.

T1105
Ingress Tool Transfer
MalwareElise

Elise can download additional files from the C2 server for execution.

T1547.001
Registry Run Keys / Startup Folder
MalwareElise

If establishing persistence by installation as a new service fails, one variant of Elise establishes persistence for the created .exe file by setting the following Registry key: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\svchost : %APPDATA%\Microsoft\Network\svchost.exe. Other variants have set the following Registry keys for persistence: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\imejp : [self] and HKCU\Software\Microsoft\Windows\CurrentVersion\Run\IAStorD.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.