Dahan, A. (2017, May 24). OPERATION COBALT KITTY: A LARGE-SCALE APT IN ASIA CARRIED OUT BY THE OCEANLOTUS GROUP. Retrieved November 5, 2018.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003 OS Credential Dumping |
GroupAPT32 | APT32 used GetPassword_x64 to harvest credentials. |
| T1003.001 LSASS Memory |
GroupAPT32 | APT32 used Mimikatz and customized versions of Windows Credential Dumper to harvest credentials. |
| T1027.013 Encrypted/Encoded File |
GroupAPT32 | APT32 has performed code obfuscation, including encoding payloads using Base64 and using a framework called "Dont-Kill-My-Cat (DKMC). APT32 also encrypts the library used for network exfiltration with AES-256 in CBC mode in their macOS backdoor. |
| T1053.005 Scheduled Task |
GroupAPT32 | APT32 has used scheduled tasks to persist on victim systems. |
| T1059.001 PowerShell |
GroupAPT32 | APT32 has used PowerShell-based tools, PowerShell one-liners, and shellcode loaders for execution. |
| T1059.003 Windows Command Shell |
MalwareDenis | Denis can launch a remote shell to execute arbitrary commands on the victim’s machine. |
| T1059.005 Visual Basic |
GroupAPT32 | APT32 has used macros, COM scriptlets, and VBS scripts. |
| T1070.004 File Deletion |
MalwareDenis | Denis has a command to delete files from the victim’s machine. |
| T1071.003 Mail Protocols |
GroupAPT32 | APT32 has used email for C2 via an Office macro. |
| T1071.004 DNS |
MalwareDenis | Denis has used DNS tunneling for C2 communications. |
| T1083 File and Directory Discovery |
MalwareDenis | Denis has several commands to search directories for files. |
| T1137 Office Application Startup |
GroupAPT32 | APT32 have replaced Microsoft Outlook's VbaProject.OTM file to install a backdoor macro for persistence. |
| T1204.002 Malicious File |
GroupAPT32 | APT32 has attempted to lure users to execute a malicious dropper delivered via a spearphishing attachment. |
| T1218.005 Mshta |
GroupAPT32 | APT32 has used mshta.exe for code execution. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupAPT32 | APT32 established persistence using Registry Run keys, both to execute PowerShell and VBS scripts as well as to execute their backdoor directly. |
| T1552.002 Credentials in Registry |
GroupAPT32 | APT32 used Outlook Credential Dumper to harvest credentials stored in Windows registry. |
| T1566.001 Spearphishing Attachment |
GroupAPT32 | APT32 has sent spearphishing emails with a malicious executable disguised as a document or spreadsheet. |
| T1566.002 Spearphishing Link |
GroupAPT32 | APT32 has sent spearphishing emails containing malicious links. |
| T1574.001 DLL |
MalwareDenis | Denis exploits a security vulnerability to load a fake DLL and execute its code. |
| T1574.001 DLL |
GroupAPT32 | APT32 ran legitimately-signed executables from Symantec and McAfee which load a malicious DLL. The group also side-loads its backdoor by dropping a library and a legitimate, signed executable (AcroTranscoder). |
| T1588.002 Tool |
GroupAPT32 | APT32 has obtained and used tools such as Mimikatz and Cobalt Strike, and a variety of other open-source tools from GitHub. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.