Falcone, R., Lee, B. (2018, November 20). Sofacy Continues Global Attacks and Wheels Out New ‘Cannon’ Trojan. Retrieved November 26, 2018.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1033 System Owner/User Discovery |
MalwareCannon | Cannon can gather the username from the system. |
| T1041 Exfiltration Over C2 Channel |
MalwareCannon | Cannon exfiltrates collected data over email via SMTP/S and POP3/S C2 channels. |
| T1057 Process Discovery |
MalwareCannon | Cannon can obtain a list of processes running on the system. |
| T1057 Process Discovery |
MalwareZebrocy | Zebrocy uses the |
| T1059.003 Windows Command Shell |
GroupAPT28 | An APT28 loader Trojan uses a cmd.exe and batch script to run its payload. The group has also used macros to execute payloads. |
| T1071.001 Web Protocols |
MalwareZebrocy | Zebrocy uses HTTP for C2. |
| T1071.003 Mail Protocols |
MalwareCannon | Cannon uses SMTP/S and POP3/S for C2 communications by sending and receiving emails. |
| T1071.003 Mail Protocols |
MalwareZebrocy | Zebrocy uses SMTP and POP3 for C2. |
| T1082 System Information Discovery |
MalwareZebrocy | Zebrocy collects the OS version and computer name. Zebrocy also runs the |
| T1082 System Information Discovery |
MalwareCannon | Cannon can gather system information from the victim’s machine such as the OS version, and machine name. |
| T1083 File and Directory Discovery |
MalwareCannon | Cannon can obtain victim drive information as well as a list of folders in C:\Program Files. |
| T1105 Ingress Tool Transfer |
MalwareZebrocy | Zebrocy obtains additional code to execute on the victim's machine, including the downloading of a secondary payload. |
| T1105 Ingress Tool Transfer |
MalwareCannon | Cannon can download a payload for execution. |
| T1113 Screen Capture |
MalwareCannon | Cannon can take a screenshot of the desktop. |
| T1113 Screen Capture |
MalwareZebrocy | A variant of Zebrocy captures screenshots of the victim’s machine in JPEG and BMP format. |
| T1120 Peripheral Device Discovery |
MalwareZebrocy | Zebrocy enumerates information about connected storage devices. |
| T1124 System Time Discovery |
MalwareCannon | Cannon can collect the current time zone information from the victim’s machine. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareZebrocy | Zebrocy decodes its secondary payload and writes it to the victim’s machine. Zebrocy also uses AES and XOR to decrypt strings and payloads. |
| T1547.004 Winlogon Helper DLL |
MalwareCannon | Cannon adds the Registry key |
| T1680 Local Storage Discovery |
MalwareCannon | Cannon can gather drive information from the victim's machine. |
| T1680 Local Storage Discovery |
MalwareZebrocy | Zebrocy collects the serial number for the storage volume C:\. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.