ATT&CKReferencesSentinelOne NobleBaron June 2021

SentinelOne NobleBaron June 2021

Guerrero-Saade, J. (2021, June 1). NobleBaron | New Poisoned Installers Could Be Used In Supply Chain Attacks. Retrieved August 4, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples5

TechniqueUsed byProcedure example
T1027.001
Binary Padding
GroupAPT29

APT29 used large size files to avoid detection by security solutions with hardcoded size limits.

T1036
Masquerading
MalwareNativeZone

NativeZone has, upon execution, displayed a message box that appears to be related to a Ukrainian electronic document management system.

T1036.005
Match Legitimate Resource Name or Location
GroupAPT29

APT29 has renamed malicious DLLs with legitimate names to appear benign; they have also created an Azure AD certificate with a Common Name that matched the display name of the compromised service principal.

T1218.011
Rundll32
MalwareNativeZone

NativeZone has used rundll32 to execute a malicious DLL.

T1480
Execution Guardrails
MalwareNativeZone

NativeZone can check for the presence of KM.EkeyAlmaz1C.dll and will halt execution unless it is in the same directory as the rest of the malware's components.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.