ATT&CKReferencesForcepoint Monsoon

Forcepoint Monsoon

Settle, A., et al. (2016, August 8). MONSOON - Analysis Of An APT Campaign. Retrieved September 22, 2016.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software4

Campaigns0

None recorded.

Procedure examples33

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareBADNEWS

When it first starts, BADNEWS crawls the victim's local drives and collects documents with the following extensions: .doc, .docx, .pdf, .ppt, .pptx, and .txt.

T1016
System Network Configuration Discovery
MalwareUnknown Logger

Unknown Logger can obtain information about the victim's IP address.

T1020
Automated Exfiltration
MalwareTINYTYPHON

When a document is found matching one of the extensions in the configuration, TINYTYPHON uploads it to the C2 server.

T1027.013
Encrypted/Encoded File
MalwareTINYTYPHON

TINYTYPHON has used XOR with 0x90 to obfuscate its configuration file.

T1033
System Owner/User Discovery
MalwareUnknown Logger

Unknown Logger can obtain information about the victim usernames.

T1039
Data from Network Shared Drive
MalwareBADNEWS

When it first starts, BADNEWS crawls the victim's mapped drives and collects documents with the following extensions: .doc, .docx, .pdf, .ppt, .pptx, and .txt.

T1055.012
Process Hollowing
MalwareBADNEWS

BADNEWS has a command to download an .exe and use process hollowing to inject it into a new process.

T1056.001
Keylogging
MalwareBADNEWS

When it first starts, BADNEWS spawns a new thread to log keystrokes.

T1056.001
Keylogging
MalwareUnknown Logger

Unknown Logger is capable of recording keystrokes.

T1059.001
PowerShell
MalwareAutoIt backdoor

AutoIt backdoor downloads a PowerShell script that decodes to a typical shellcode loader.

T1059.003
Windows Command Shell
MalwareBADNEWS

BADNEWS is capable of executing commands via cmd.exe.

T1074.001
Local Data Staging
MalwareBADNEWS

BADNEWS copies documents under 15MB found on the victim system to is the user's %temp%\SMB\ folder. It also copies files from USB devices to a predefined directory.

T1082
System Information Discovery
MalwareUnknown Logger

Unknown Logger can obtain information about the victim computer name, physical memory, country, and date.

T1083
File and Directory Discovery
MalwareTINYTYPHON

TINYTYPHON searches through the drive containing the OS, then all drive letters C through to Z, for documents matching certain extensions.

T1083
File and Directory Discovery
MalwareAutoIt backdoor

AutoIt backdoor is capable of identifying documents on the victim with the following extensions: .doc; .pdf, .csv, .ppt, .docx, .pst, .xls, .xlsx, .pptx, and .jpeg.

T1091
Replication Through Removable Media
MalwareUnknown Logger

Unknown Logger is capable of spreading to USB devices.

T1102.001
Dead Drop Resolver
MalwareBADNEWS

BADNEWS collects C2 information via a dead drop resolver.

T1102.002
Bidirectional Communication
MalwareBADNEWS

BADNEWS can use multiple C2 channels, including RSS feeds, Github, forums, and blogs.

T1105
Ingress Tool Transfer
MalwareUnknown Logger

Unknown Logger is capable of downloading remote files.

T1105
Ingress Tool Transfer
MalwareBADNEWS

BADNEWS is capable of downloading additional files through C2 channels, including a new version of itself.

T1106
Native API
MalwareBADNEWS

BADNEWS has a command to download an .exe and execute it via CreateProcess API. It can also run with ShellExecute.

T1113
Screen Capture
MalwareBADNEWS

BADNEWS has a command to take a screenshot and send it to the C2 server.

T1120
Peripheral Device Discovery
MalwareBADNEWS

BADNEWS checks for new hard drives on the victim, such as USB devices, by listening for the WM_DEVICECHANGE window message.

T1132
Data Encoding
MalwareBADNEWS

After encrypting C2 data, BADNEWS converts it into a hexadecimal representation and then encodes it into base64.

T1132.001
Standard Encoding
MalwareBADNEWS

BADNEWS encodes C2 traffic with base64.

T1132.001
Standard Encoding
MalwareAutoIt backdoor

AutoIt backdoor has sent a C2 response that was base64-encoded.

T1547.001
Registry Run Keys / Startup Folder
MalwareTINYTYPHON

TINYTYPHON installs itself under Registry Run key to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareBADNEWS

BADNEWS installs a registry Run key to establish persistence.

T1548.002
Bypass User Account Control
MalwareAutoIt backdoor

AutoIt backdoor attempts to escalate privileges by bypassing User Access Control.

T1555.003
Credentials from Web Browsers
MalwareUnknown Logger

Unknown Logger is capable of stealing usernames and passwords from browsers on the victim machine.

T1573.001
Symmetric Cryptography
MalwareBADNEWS

BADNEWS encrypts C2 data with a ROR by 3 and an XOR by 0x23.

T1574.001
DLL
MalwareBADNEWS

BADNEWS typically loads its DLL file into a legitimate signed Java or VMware executable.

T1685
Disable or Modify Tools
MalwareUnknown Logger

Unknown Logger has functionality to disable security tools, including Kaspersky, BitDefender, and MalwareBytes.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.