ATT&CKReferencesIBM TA505 April 2020

IBM TA505 April 2020

Frydrych, M. (2020, April 14). TA505 Continues to Infect Networks With SDBbot RAT. Retrieved May 29, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples12

TechniqueUsed byProcedure example
T1027.002
Software Packing
GroupTA505

TA505 has used UPX to obscure malicious code.

T1027.002
Software Packing
MalwareSDBbot

SDBbot has used a packed installer file.

T1055.001
Dynamic-link Library Injection
GroupTA505

TA505 has been seen injecting a DLL into winword.exe.

T1059.005
Visual Basic
GroupTA505

TA505 has used VBS for code execution.

T1069
Permission Groups Discovery
GroupTA505

TA505 has used TinyMet to enumerate members of privileged groups. TA505 has also run net group /domain.

T1071.001
Web Protocols
GroupTA505

TA505 has used HTTP to communicate with C2 nodes.

T1078.002
Domain Accounts
GroupTA505

TA505 has used stolen domain admin accounts to compromise additional hosts.

T1125
Video Capture
MalwareSDBbot

SDBbot has the ability to record video on a compromised host.

T1140
Deobfuscate/Decode Files or Information
MalwareSDBbot

SDBbot has the ability to decrypt and decompress its payload to enable code execution.

T1204.002
Malicious File
GroupTA505

TA505 has used lures to get users to enable content in malicious attachments and execute malicious files contained in archives. For example, TA505 makes their malware look like legitimate Microsoft Word documents, .pdf and/or .lnk files.

T1547.001
Registry Run Keys / Startup Folder
MalwareSDBbot

SDBbot has the ability to add a value to the Registry Run key to establish persistence if it detects it is running with regular user privilege.

T1566.001
Spearphishing Attachment
GroupTA505

TA505 has used spearphishing emails with malicious attachments to initially compromise victims.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.