ATT&CKReferencesFireEye APT10 Sept 2018

FireEye APT10 Sept 2018

Matsuda, A., Muhammad I. (2018, September 13). APT10 Targeting Japanese Corporations Using Updated TTPs. Retrieved September 17, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples19

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareUPPERCUT

UPPERCUT has the capability to gather the victim's proxy information.

T1027.013
Encrypted/Encoded File
GroupmenuPass

menuPass has encoded strings in its malware with base64 as well as with a simple, single-byte XOR obfuscation using key 0x40.

T1033
System Owner/User Discovery
MalwareUPPERCUT

UPPERCUT has the capability to collect the current logged on user’s username from a machine.

T1036
Masquerading
GroupmenuPass

menuPass has used esentutl to change file extensions to their true type that were masquerading as .txt files.

T1036.003
Rename Legitimate Utilities
GroupmenuPass

menuPass has renamed certutil and moved it to a different location on the system to avoid detection based on use of the tool.

T1059.003
Windows Command Shell
GroupmenuPass

menuPass executes commands using a command-line interface and reverse shell. The group has used a modified version of pentesting script wmiexec.vbs to execute commands. menuPass has used malicious macros embedded inside Office documents to execute files.

T1059.003
Windows Command Shell
MalwareUPPERCUT

UPPERCUT uses cmd.exe to execute commands on the victim’s machine.

T1071.001
Web Protocols
MalwareUPPERCUT

UPPERCUT has used HTTP for C2, including sending error codes in cookie headers.

T1082
System Information Discovery
MalwareUPPERCUT

UPPERCUT has the capability to gather the system’s hostname and OS version.

T1083
File and Directory Discovery
MalwareUPPERCUT

UPPERCUT has the capability to gather the victim's current directory.

T1090.002
External Proxy
GroupmenuPass

menuPass has used a global service provider's IP as a proxy for C2 traffic from a victim.

T1105
Ingress Tool Transfer
MalwareUPPERCUT

UPPERCUT can download and upload files to and from the victim’s machine.

T1113
Screen Capture
MalwareUPPERCUT

UPPERCUT can capture desktop screenshots in the PNG format and send them to the C2 server.

T1124
System Time Discovery
MalwareUPPERCUT

UPPERCUT has the capability to obtain the time zone information and the current timestamp of the victim’s machine.

T1140
Deobfuscate/Decode Files or Information
GroupmenuPass

menuPass has used certutil in a macro to decode base64-encoded content contained in a dropper document attached to an email. The group has also used certutil -decode to decode files on the victim’s machine when dropping UPPERCUT.

T1204.002
Malicious File
GroupmenuPass

menuPass has attempted to get victims to open malicious files such as Windows Shortcuts (.lnk) and/or Microsoft Office documents, sent via email as part of spearphishing campaigns.

T1566.001
Spearphishing Attachment
GroupmenuPass

menuPass has sent malicious Office documents via email as part of spearphishing campaigns as well as executables disguised as documents.

T1573.001
Symmetric Cryptography
MalwareUPPERCUT

Some versions of UPPERCUT have used the hard-coded string “this is the encrypt key” for Blowfish encryption when communicating with a C2. Later versions have hard-coded keys uniquely for each C2 address. UPPERCUT has also used custom ChaCha20, XOR, and LZO algorithms for C2 communication.

T1574.001
DLL
GroupmenuPass

menuPass has used DLL side-loading to launch versions of Mimikatz and PwDump6 as well as UPPERCUT. menuPass has also used DLL search order hijacking.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.