Matsuda, A., Muhammad I. (2018, September 13). APT10 Targeting Japanese Corporations Using Updated TTPs. Retrieved September 17, 2018.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareUPPERCUT | UPPERCUT has the capability to gather the victim's proxy information. |
| T1027.013 Encrypted/Encoded File |
GroupmenuPass | menuPass has encoded strings in its malware with base64 as well as with a simple, single-byte XOR obfuscation using key 0x40. |
| T1033 System Owner/User Discovery |
MalwareUPPERCUT | UPPERCUT has the capability to collect the current logged on user’s username from a machine. |
| T1036 Masquerading |
GroupmenuPass | menuPass has used esentutl to change file extensions to their true type that were masquerading as .txt files. |
| T1036.003 Rename Legitimate Utilities |
GroupmenuPass | menuPass has renamed certutil and moved it to a different location on the system to avoid detection based on use of the tool. |
| T1059.003 Windows Command Shell |
GroupmenuPass | menuPass executes commands using a command-line interface and reverse shell. The group has used a modified version of pentesting script wmiexec.vbs to execute commands. menuPass has used malicious macros embedded inside Office documents to execute files. |
| T1059.003 Windows Command Shell |
MalwareUPPERCUT | UPPERCUT uses cmd.exe to execute commands on the victim’s machine. |
| T1071.001 Web Protocols |
MalwareUPPERCUT | UPPERCUT has used HTTP for C2, including sending error codes in cookie headers. |
| T1082 System Information Discovery |
MalwareUPPERCUT | UPPERCUT has the capability to gather the system’s hostname and OS version. |
| T1083 File and Directory Discovery |
MalwareUPPERCUT | UPPERCUT has the capability to gather the victim's current directory. |
| T1090.002 External Proxy |
GroupmenuPass | menuPass has used a global service provider's IP as a proxy for C2 traffic from a victim. |
| T1105 Ingress Tool Transfer |
MalwareUPPERCUT | UPPERCUT can download and upload files to and from the victim’s machine. |
| T1113 Screen Capture |
MalwareUPPERCUT | UPPERCUT can capture desktop screenshots in the PNG format and send them to the C2 server. |
| T1124 System Time Discovery |
MalwareUPPERCUT | UPPERCUT has the capability to obtain the time zone information and the current timestamp of the victim’s machine. |
| T1140 Deobfuscate/Decode Files or Information |
GroupmenuPass | menuPass has used certutil in a macro to decode base64-encoded content contained in a dropper document attached to an email. The group has also used |
| T1204.002 Malicious File |
GroupmenuPass | menuPass has attempted to get victims to open malicious files such as Windows Shortcuts (.lnk) and/or Microsoft Office documents, sent via email as part of spearphishing campaigns. |
| T1566.001 Spearphishing Attachment |
GroupmenuPass | menuPass has sent malicious Office documents via email as part of spearphishing campaigns as well as executables disguised as documents. |
| T1573.001 Symmetric Cryptography |
MalwareUPPERCUT | Some versions of UPPERCUT have used the hard-coded string “this is the encrypt key” for Blowfish encryption when communicating with a C2. Later versions have hard-coded keys uniquely for each C2 address. UPPERCUT has also used custom ChaCha20, XOR, and LZO algorithms for C2 communication. |
| T1574.001 DLL |
GroupmenuPass | menuPass has used DLL side-loading to launch versions of Mimikatz and PwDump6 as well as UPPERCUT. menuPass has also used DLL search order hijacking. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.