ATT&CKReferencesMandiant UNC3313 Feb 2022

Mandiant UNC3313 Feb 2022

Tomcik, R. et al. (2022, February 24). Left On Read: Telegram Malware Spotted in Latest Iranian Cyber Espionage Activity. Retrieved August 18, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software2

Campaigns0

None recorded.

Procedure examples8

TechniqueUsed byProcedure example
T1033
System Owner/User Discovery
MalwareSTARWHALE

STARWHALE can gather the username from an infected host.

T1059.003
Windows Command Shell
MalwareSTARWHALE

STARWHALE has the ability to execute commands via `cmd.exe`.

T1059.005
Visual Basic
MalwareSTARWHALE

STARWHALE can use the VBScript function `GetRef` as part of its persistence mechanism.

T1071.001
Web Protocols
MalwareSTARWHALE

STARWHALE has the ability to contact actor-controlled C2 servers via HTTP.

T1074.001
Local Data Staging
MalwareSTARWHALE

STARWHALE has stored collected data in a file called `stari.txt`.

T1082
System Information Discovery
MalwareSTARWHALE

STARWHALE can gather the computer name of an infected host.

T1543.003
Windows Service
MalwareSTARWHALE

STARWHALE has the ability to create the following Windows service to establish persistence on an infected host: `sc create Windowscarpstss binpath= "cmd.exe /c cscript.exe c:\\windows\\system32\\w7_1.wsf humpback_whale" start= "auto" obj= "LocalSystem"`.

T1547.001
Registry Run Keys / Startup Folder
MalwareSTARWHALE

STARWHALE can establish persistence by installing itself in the startup folder, whereas the GO variant has created a `HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OutlookM` registry key.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.