ATT&CKReferencesFireEye APT38 Oct 2018

FireEye APT38 Oct 2018

FireEye. (2018, October 03). APT38: Un-usual Suspects. Retrieved November 17, 2024.

Open the source

Techniques3

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples19

TechniqueUsed byProcedure example
T1027.002
Software Packing
GroupAPT38

APT38 has used several code packing methods such as Themida, Enigma, VMProtect, and Obsidium, to pack their implants.

T1049
System Network Connections Discovery
GroupAPT38

APT38 installed a port monitoring tool, MAPMAKER, to print the active TCP connections on the local system.

T1056.001
Keylogging
GroupAPT38

APT38 used a Trojan called KEYLIME to capture keystrokes from the victim’s machine.

T1057
Process Discovery
GroupAPT38

APT38 leveraged Sysmon to understand the processes, services in the organization.

T1059.003
Windows Command Shell
GroupAPT38

APT38 has used a command-line tunneler, NACHOCHEESE, to give them shell access to a victim’s machine. Additionally, APT38 has used batch scripts.

T1070.004
File Deletion
GroupAPT38

APT38 has used a utility called CLOSESHAVE that can securely delete a file from the system. They have also removed malware, tools, or other non-native files used during the intrusion to reduce their footprint or as part of the post-intrusion cleanup process.

T1071.001
Web Protocols
GroupAPT38

APT38 used a backdoor, QUICKRIDE, to communicate to the C2 server over HTTP and HTTPS.

T1105
Ingress Tool Transfer
GroupAPT38

APT38 used a backdoor, NESTEGG, that has the capability to download and upload files to and from a victim’s machine. Additionally, APT38 has downloaded other payloads onto a victim’s machine.

T1112
Modify Registry
GroupAPT38

APT38 uses a tool called CLEANTOAD that has the capability to modify Registry keys.

T1115
Clipboard Data
GroupAPT38

APT38 used a Trojan called KEYLIME to collect data from the clipboard.

T1189
Drive-by Compromise
GroupAPT38

APT38 has conducted watering holes schemes to gain initial access to victims.

T1485
Data Destruction
GroupAPT38

APT38 has used a custom secure delete function to make deleted files unrecoverable.

T1486
Data Encrypted for Impact
GroupAPT38

APT38 has used Hermes ransomware to encrypt files with AES256.

T1529
System Shutdown/Reboot
GroupAPT38

APT38 has used a custom MBR wiper named BOOTWRECK, which will initiate a system reboot after wiping the victim's MBR.

T1561.002
Disk Structure Wipe
GroupAPT38

APT38 has used a custom MBR wiper named BOOTWRECK to render systems inoperable.

T1565.001
Stored Data Manipulation
GroupAPT38

APT38 has used DYEPACK to create, delete, and alter records in databases used for SWIFT transactions.

T1565.002
Transmitted Data Manipulation
GroupAPT38

APT38 has used DYEPACK to manipulate SWIFT messages en route to a printer.

T1565.003
Runtime Data Manipulation
GroupAPT38

APT38 has used DYEPACK.FOX to manipulate PDF data as it is accessed to remove traces of fraudulent SWIFT transactions from the data displayed to the end user.

T1685.005
Clear Windows Event Logs
GroupAPT38

APT38 clears Window Event logs and Sysmon logs from the system.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.