ATT&CKReferencesCISA Iran Albanian Attacks September 2022

CISA Iran Albanian Attacks September 2022

CISA. (2022, September 23). AA22-264A Iranian State Actors Conduct Cyber Operations Against the Government of Albania. Retrieved August 6, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns1

Procedure examples27

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
CampaignHomeLand Justice

During HomeLand Justice, threat actors dumped LSASS memory on compromised hosts.

T1021.001
Remote Desktop Protocol
CampaignHomeLand Justice

During HomeLand Justice, threat actors primarily used RDP for lateral movement in the victim environment.

T1021.002
SMB/Windows Admin Shares
CampaignHomeLand Justice

During HomeLand Justice, threat actors used SMB for lateral movement.

T1027.013
Encrypted/Encoded File
MalwareROADSWEEP

The ROADSWEEP binary contains RC4 encrypted embedded scripts.

T1036.005
Match Legitimate Resource Name or Location
CampaignHomeLand Justice

During HomeLand Justice, threat actors renamed ROADSWEEP to GoXML.exe and ZeroCleare to cl.exe.

T1041
Exfiltration Over C2 Channel
CampaignHomeLand Justice

During HomeLand Justice, threat actors used HTTP to transfer data from compromised Exchange servers.

T1046
Network Service Discovery
CampaignHomeLand Justice

During HomeLand Justice, threat actors executed the Advanced Port Scanner tool on compromised systems.

T1059.001
PowerShell
CampaignHomeLand Justice

During HomeLand Justice, threat actors used PowerShell cmdlets New-MailboxSearch and Get-Recipient for discovery.

T1059.003
Windows Command Shell
CampaignHomeLand Justice

During HomeLand Justice, threat actors used Windows batch files for persistence and execution.

T1070.004
File Deletion
MalwareZeroCleare

ZeroCleare has the ability to uninstall the RawDisk driver and delete the `rwdsk` file on disk.

T1078
Valid Accounts
CampaignHomeLand Justice

During HomeLand Justice, threat actors used a compromised Exchange account to search mailboxes and create new Exchange accounts.

T1083
File and Directory Discovery
MalwareROADSWEEP

ROADSWEEP can enumerate files on infected devices and avoid encrypting files with .exe, .dll, .sys, .lnk, or . lck extensions.

T1087.003
Email Account
CampaignHomeLand Justice

During HomeLand Justice, threat actors used compromised Exchange accounts to search mailboxes for administrator accounts.

T1114.002
Remote Email Collection
CampaignHomeLand Justice

During HomeLand Justice, threat actors made multiple HTTP POST requests to the Exchange servers of the victim organization to transfer data.

T1140
Deobfuscate/Decode Files or Information
MalwareROADSWEEP

ROADSWEEP can decrypt embedded scripts prior to execution.

T1190
Exploit Public-Facing Application
CampaignHomeLand Justice

For HomeLand Justice, threat actors exploited CVE-2019-0604 in Microsoft SharePoint for initial access.

T1480
Execution Guardrails
MalwareROADSWEEP

ROADSWEEP requires four command line arguments to execute correctly, otherwise it will produce a message box and halt execution.

T1486
Data Encrypted for Impact
CampaignHomeLand Justice

During HomeLand Justice, threat actors used ROADSWEEP ransomware to encrypt files on targeted systems.

T1486
Data Encrypted for Impact
MalwareROADSWEEP

ROADSWEEP can RC4 encrypt content in blocks on targeted systems.

T1490
Inhibit System Recovery
MalwareROADSWEEP

ROADSWEEP has the ability to disable `SystemRestore` and Volume Shadow Copies.

T1505.003
Web Shell
CampaignHomeLand Justice

For HomeLand Justice, threat actors used .aspx webshells named pickers.aspx, error4.aspx, and ClientBin.aspx, to maintain persistence.

T1553.002
Code Signing
MalwareROADSWEEP

ROADSWEEP has been digitally signed with a certificate issued to the Kuwait Telecommunications Company KSC.

T1561.002
Disk Structure Wipe
MalwareZeroCleare

ZeroCleare can corrupt the file system and wipe the system drive on targeted hosts.

T1561.002
Disk Structure Wipe
CampaignHomeLand Justice

During HomeLand Justice, threat actors used a version of ZeroCleare to wipe disk drives on targeted hosts.

T1570
Lateral Tool Transfer
CampaignHomeLand Justice

During HomeLand Justice, threat actors initiated a process named Mellona.exe to spread the ROADSWEEP file encryptor and a persistence script to a list of internal machines.

T1588.002
Tool
CampaignHomeLand Justice

During HomeLand Justice, threat actors used tools including Advanced Port Scanner, Mimikatz, and Impacket.

T1588.003
Code Signing Certificates
CampaignHomeLand Justice

During HomeLand Justice, threat actors used tools with legitimate code signing certificates.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.