ATT&CKReferencesUnit42 Cannon Nov 2018

Unit42 Cannon Nov 2018

Falcone, R., Lee, B. (2018, November 20). Sofacy Continues Global Attacks and Wheels Out New ‘Cannon’ Trojan. Retrieved November 26, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software2

Campaigns0

None recorded.

Procedure examples21

TechniqueUsed byProcedure example
T1033
System Owner/User Discovery
MalwareCannon

Cannon can gather the username from the system.

T1041
Exfiltration Over C2 Channel
MalwareCannon

Cannon exfiltrates collected data over email via SMTP/S and POP3/S C2 channels.

T1057
Process Discovery
MalwareCannon

Cannon can obtain a list of processes running on the system.

T1057
Process Discovery
MalwareZebrocy

Zebrocy uses the tasklist and wmic process get Capture, ExecutablePath commands to gather the processes running on the system.

T1059.003
Windows Command Shell
GroupAPT28

An APT28 loader Trojan uses a cmd.exe and batch script to run its payload. The group has also used macros to execute payloads.

T1071.001
Web Protocols
MalwareZebrocy

Zebrocy uses HTTP for C2.

T1071.003
Mail Protocols
MalwareCannon

Cannon uses SMTP/S and POP3/S for C2 communications by sending and receiving emails.

T1071.003
Mail Protocols
MalwareZebrocy

Zebrocy uses SMTP and POP3 for C2.

T1082
System Information Discovery
MalwareZebrocy

Zebrocy collects the OS version and computer name. Zebrocy also runs the systeminfo command to gather system information.

T1082
System Information Discovery
MalwareCannon

Cannon can gather system information from the victim’s machine such as the OS version, and machine name.

T1083
File and Directory Discovery
MalwareCannon

Cannon can obtain victim drive information as well as a list of folders in C:\Program Files.

T1105
Ingress Tool Transfer
MalwareZebrocy

Zebrocy obtains additional code to execute on the victim's machine, including the downloading of a secondary payload.

T1105
Ingress Tool Transfer
MalwareCannon

Cannon can download a payload for execution.

T1113
Screen Capture
MalwareCannon

Cannon can take a screenshot of the desktop.

T1113
Screen Capture
MalwareZebrocy

A variant of Zebrocy captures screenshots of the victim’s machine in JPEG and BMP format.

T1120
Peripheral Device Discovery
MalwareZebrocy

Zebrocy enumerates information about connected storage devices.

T1124
System Time Discovery
MalwareCannon

Cannon can collect the current time zone information from the victim’s machine.

T1140
Deobfuscate/Decode Files or Information
MalwareZebrocy

Zebrocy decodes its secondary payload and writes it to the victim’s machine. Zebrocy also uses AES and XOR to decrypt strings and payloads.

T1547.004
Winlogon Helper DLL
MalwareCannon

Cannon adds the Registry key HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon to establish persistence.

T1680
Local Storage Discovery
MalwareCannon

Cannon can gather drive information from the victim's machine.

T1680
Local Storage Discovery
MalwareZebrocy

Zebrocy collects the serial number for the storage volume C:\.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.