ATT&CKReferencesMicrosoft Albanian Government Attacks September 2022

Microsoft Albanian Government Attacks September 2022

MSTIC. (2022, September 8). Microsoft investigates Iranian attacks against the Albanian government. Retrieved August 6, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns1

Procedure examples25

TechniqueUsed byProcedure example
T1021.001
Remote Desktop Protocol
CampaignHomeLand Justice

During HomeLand Justice, threat actors primarily used RDP for lateral movement in the victim environment.

T1021.002
SMB/Windows Admin Shares
CampaignHomeLand Justice

During HomeLand Justice, threat actors used SMB for lateral movement.

T1027.013
Encrypted/Encoded File
MalwareROADSWEEP

The ROADSWEEP binary contains RC4 encrypted embedded scripts.

T1046
Network Service Discovery
CampaignHomeLand Justice

During HomeLand Justice, threat actors executed the Advanced Port Scanner tool on compromised systems.

T1047
Windows Management Instrumentation
CampaignHomeLand Justice

During HomeLand Justice, threat actors used WMI to modify Windows Defender settings.

T1059.001
PowerShell
CampaignHomeLand Justice

During HomeLand Justice, threat actors used PowerShell cmdlets New-MailboxSearch and Get-Recipient for discovery.

T1059.003
Windows Command Shell
MalwareROADSWEEP

ROADSWEEP can open cmd.exe to enable command execution.

T1059.003
Windows Command Shell
CampaignHomeLand Justice

During HomeLand Justice, threat actors used Windows batch files for persistence and execution.

T1070.004
File Deletion
MalwareROADSWEEP

ROADSWEEP can use embedded scripts to remove itself from the infected host.

T1078.001
Default Accounts
CampaignHomeLand Justice

During HomeLand Justice, threat actors used the built-in administrator account to move laterally using RDP and Impacket.

T1083
File and Directory Discovery
MalwareROADSWEEP

ROADSWEEP can enumerate files on infected devices and avoid encrypting files with .exe, .dll, .sys, .lnk, or . lck extensions.

T1098.002
Additional Email Delegate Permissions
CampaignHomeLand Justice

During HomeLand Justice, threat actors added the `ApplicationImpersonation` management role to accounts under their control to impersonate users and take ownership of targeted mailboxes.

T1105
Ingress Tool Transfer
CampaignHomeLand Justice

During HomeLand Justice, threat actors used web shells to download files to compromised infrastructure.

T1134.001
Token Impersonation/Theft
CampaignHomeLand Justice

During HomeLand Justice, threat actors used custom tooling to acquire tokens using `ImpersonateLoggedOnUser/SetThreadToken`.

T1480
Execution Guardrails
MalwareROADSWEEP

ROADSWEEP requires four command line arguments to execute correctly, otherwise it will produce a message box and halt execution.

T1486
Data Encrypted for Impact
MalwareROADSWEEP

ROADSWEEP can RC4 encrypt content in blocks on targeted systems.

T1486
Data Encrypted for Impact
CampaignHomeLand Justice

During HomeLand Justice, threat actors used ROADSWEEP ransomware to encrypt files on targeted systems.

T1491.001
Internal Defacement
MalwareROADSWEEP

ROADSWEEP has dropped ransom notes in targeted folders prior to encrypting the files.

T1505.003
Web Shell
CampaignHomeLand Justice

For HomeLand Justice, threat actors used .aspx webshells named pickers.aspx, error4.aspx, and ClientBin.aspx, to maintain persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareROADSWEEP

ROADSWEEP has been placed in the start up folder to trigger execution upon user login.

T1561.002
Disk Structure Wipe
CampaignHomeLand Justice

During HomeLand Justice, threat actors used a version of ZeroCleare to wipe disk drives on targeted hosts.

T1588.002
Tool
CampaignHomeLand Justice

During HomeLand Justice, threat actors used tools including Advanced Port Scanner, Mimikatz, and Impacket.

T1680
Local Storage Discovery
MalwareROADSWEEP

ROADSWEEP can enumerate logical drives on targeted devices.

T1685
Disable or Modify Tools
CampaignHomeLand Justice

During HomeLand Justice, threat actors modified and disabled components of endpoint detection and response (EDR) solutions including Microsoft Defender Antivirus.

T1685.001
Disable or Modify Windows Event Log
CampaignHomeLand Justice

During HomeLand Justice, threat actors deleted Windows events and application logs.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.