ATT&CKReferencesCybereason Oceanlotus May 2017

Cybereason Oceanlotus May 2017

Dahan, A. (2017, May 24). OPERATION COBALT KITTY: A LARGE-SCALE APT IN ASIA CARRIED OUT BY THE OCEANLOTUS GROUP. Retrieved November 5, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples21

TechniqueUsed byProcedure example
T1003
OS Credential Dumping
GroupAPT32

APT32 used GetPassword_x64 to harvest credentials.

T1003.001
LSASS Memory
GroupAPT32

APT32 used Mimikatz and customized versions of Windows Credential Dumper to harvest credentials.

T1027.013
Encrypted/Encoded File
GroupAPT32

APT32 has performed code obfuscation, including encoding payloads using Base64 and using a framework called "Dont-Kill-My-Cat (DKMC). APT32 also encrypts the library used for network exfiltration with AES-256 in CBC mode in their macOS backdoor.

T1053.005
Scheduled Task
GroupAPT32

APT32 has used scheduled tasks to persist on victim systems.

T1059.001
PowerShell
GroupAPT32

APT32 has used PowerShell-based tools, PowerShell one-liners, and shellcode loaders for execution.

T1059.003
Windows Command Shell
MalwareDenis

Denis can launch a remote shell to execute arbitrary commands on the victim’s machine.

T1059.005
Visual Basic
GroupAPT32

APT32 has used macros, COM scriptlets, and VBS scripts.

T1070.004
File Deletion
MalwareDenis

Denis has a command to delete files from the victim’s machine.

T1071.003
Mail Protocols
GroupAPT32

APT32 has used email for C2 via an Office macro.

T1071.004
DNS
MalwareDenis

Denis has used DNS tunneling for C2 communications.

T1083
File and Directory Discovery
MalwareDenis

Denis has several commands to search directories for files.

T1137
Office Application Startup
GroupAPT32

APT32 have replaced Microsoft Outlook's VbaProject.OTM file to install a backdoor macro for persistence.

T1204.002
Malicious File
GroupAPT32

APT32 has attempted to lure users to execute a malicious dropper delivered via a spearphishing attachment.

T1218.005
Mshta
GroupAPT32

APT32 has used mshta.exe for code execution.

T1547.001
Registry Run Keys / Startup Folder
GroupAPT32

APT32 established persistence using Registry Run keys, both to execute PowerShell and VBS scripts as well as to execute their backdoor directly.

T1552.002
Credentials in Registry
GroupAPT32

APT32 used Outlook Credential Dumper to harvest credentials stored in Windows registry.

T1566.001
Spearphishing Attachment
GroupAPT32

APT32 has sent spearphishing emails with a malicious executable disguised as a document or spreadsheet.

T1566.002
Spearphishing Link
GroupAPT32

APT32 has sent spearphishing emails containing malicious links.

T1574.001
DLL
MalwareDenis

Denis exploits a security vulnerability to load a fake DLL and execute its code.

T1574.001
DLL
GroupAPT32

APT32 ran legitimately-signed executables from Symantec and McAfee which load a malicious DLL. The group also side-loads its backdoor by dropping a library and a legitimate, signed executable (AcroTranscoder).

T1588.002
Tool
GroupAPT32

APT32 has obtained and used tools such as Mimikatz and Cobalt Strike, and a variety of other open-source tools from GitHub.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.