ATT&CKReferencesCheck Point APT34 April 2021

Check Point APT34 April 2021

Check Point. (2021, April 8). Iran’s APT34 Returns with an Updated Arsenal. Retrieved May 5, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples24

TechniqueUsed byProcedure example
T1001
Data Obfuscation
MalwareSideTwist

SideTwist can embed C2 responses in the source code of a fake Flickr webpage.

T1005
Data from Local System
MalwareSideTwist

SideTwist has the ability to upload files from a compromised host.

T1008
Fallback Channels
MalwareSideTwist

SideTwist has primarily used port 443 for C2 but can use port 80 as a fallback.

T1016
System Network Configuration Discovery
MalwareSideTwist

SideTwist has the ability to collect the domain name on a compromised host.

T1033
System Owner/User Discovery
MalwareSideTwist

SideTwist can collect the username on a targeted system.

T1033
System Owner/User Discovery
GroupOilRig

OilRig has run whoami on a victim.

T1036
Masquerading
GroupOilRig

OilRig has used .doc file extensions to mask malicious executables.

T1041
Exfiltration Over C2 Channel
MalwareSideTwist

SideTwist has exfiltrated data over its C2 channel.

T1053.005
Scheduled Task
GroupOilRig

OilRig has created scheduled tasks that run a VBScript to execute a payload on victim machines.

T1059.003
Windows Command Shell
MalwareSideTwist

SideTwist can execute shell commands on a compromised host.

T1059.005
Visual Basic
GroupOilRig

OilRig has used VBScript macros for execution on compromised hosts.

T1071.001
Web Protocols
MalwareSideTwist

SideTwist has used HTTP GET and POST requests over port 443 for C2.

T1071.004
DNS
GroupOilRig

OilRig has used DNS for C2 including the publicly available requestbin.net tunneling service.

T1082
System Information Discovery
MalwareSideTwist

SideTwist can collect the computer name of a targeted system.

T1082
System Information Discovery
GroupOilRig

OilRig has run hostname and systeminfo on a victim.

T1083
File and Directory Discovery
MalwareSideTwist

SideTwist has the ability to search for specific files.

T1105
Ingress Tool Transfer
MalwareSideTwist

SideTwist has the ability to download additional files.

T1106
Native API
MalwareSideTwist

SideTwist can use GetUserNameW, GetComputerNameW, and GetComputerNameExW to gather information.

T1120
Peripheral Device Discovery
GroupOilRig

OilRig has used tools to identify if a mouse is connected to a targeted system.

T1132.001
Standard Encoding
MalwareSideTwist

SideTwist has used Base64 for encoded C2 traffic.

T1140
Deobfuscate/Decode Files or Information
MalwareSideTwist

SideTwist can decode and decrypt messages received from C2.

T1204.002
Malicious File
GroupOilRig

OilRig has delivered macro-enabled documents that required targets to click the "enable content" button to execute the payload on the system.

T1497.001
System Checks
GroupOilRig

OilRig has used macros to verify if a mouse is connected to a compromised machine.

T1573.001
Symmetric Cryptography
MalwareSideTwist

SideTwist can encrypt C2 communications with a randomly generated key.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.