ATT&CKReferencesTrend Micro Black Basta October 2022

Trend Micro Black Basta October 2022

Kenefick, I. et al. (2022, October 12). Black Basta Ransomware Gang Infiltrates Networks via QAKBOT, Brute Ratel, and Cobalt Strike. Retrieved February 6, 2023.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples28

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareQakBot

QakBot can use net config workstation, arp -a, `nslookup`, and ipconfig /all to gather network configuration information.

T1018
Remote System Discovery
MalwareQakBot

QakBot can identify remote systems through the net view command.

T1021.002
SMB/Windows Admin Shares
MalwareCobalt Strike

Cobalt Strike can use Window admin shares (C$ and ADMIN$) for lateral movement.

T1027.006
HTML Smuggling
MalwareQakBot

QakBot has been delivered in ZIP files via HTML smuggling.

T1027.010
Command Obfuscation
MalwareQakBot

QakBot can use obfuscated and encoded scripts.

T1033
System Owner/User Discovery
MalwareQakBot

QakBot can identify the user name on a compromised system.

T1036.008
Masquerade File Type
MalwareQakBot

The QakBot payload has been disguised as a PNG file and hidden within LNK files using a Microsoft File Explorer icon.

T1049
System Network Connections Discovery
MalwareQakBot

QakBot can use netstat to enumerate current network connections.

T1055
Process Injection
MalwareQakBot

QakBot can inject itself into processes including explore.exe, Iexplore.exe, Mobsync.exe., and wermgr.exe.

T1059.003
Windows Command Shell
MalwareQakBot

QakBot can use cmd.exe to launch itself and to execute multiple C2 commands.

T1059.003
Windows Command Shell
MalwareCobalt Strike

Cobalt Strike uses a command-line interface to interact with systems.

T1059.005
Visual Basic
MalwareQakBot

QakBot can use VBS to download and execute malicious files.

T1059.007
JavaScript
MalwareQakBot

The QakBot web inject module can inject Java Script into web banking pages visited by the victim.

T1069.001
Local Groups
MalwareQakBot

QakBot can use net localgroup to enable discovery of local groups.

T1069.002
Domain Groups
ToolBrute Ratel C4

Brute Ratel C4 can use `net group` for discovery on targeted domains.

T1071.001
Web Protocols
ToolBrute Ratel C4

Brute Ratel C4 can use HTTPS and HTTPS for C2 communication.

T1071.004
DNS
ToolBrute Ratel C4

Brute Ratel C4 can use DNS over HTTPS for C2.

T1087.002
Domain Account
ToolBrute Ratel C4

Brute Ratel C4 can use LDAP queries, `net group "Domain Admins" /domain` and `net user /domain` for discovery.

T1204.001
Malicious Link
MalwareQakBot

QakBot has gained execution through users opening malicious links.

T1218.010
Regsvr32
MalwareQakBot

QakBot can use Regsvr32 to execute malicious DLLs.

T1218.011
Rundll32
MalwareQakBot

QakBot has used Rundll32.exe to drop malicious DLLs including Brute Ratel C4 and to enable C2 communication.

T1218.011
Rundll32
MalwareCobalt Strike

Cobalt Strike can use `rundll32.exe` to load DLL from the command line.

T1482
Domain Trust Discovery
ToolBrute Ratel C4

Brute Ratel C4 can use LDAP queries and `nltest /domain_trusts` for domain trust discovery.

T1553.005
Mark-of-the-Web Bypass
MalwareQakBot

QakBot has been packaged in ISO files in order to bypass Mark of the Web (MOTW) security measures.

T1560
Archive Collected Data
ToolBloodHound

BloodHound can compress data collected by its SharpHound ingestor into a ZIP file to be written to disk.

T1564.001
Hidden Files and Directories
MalwareQakBot

QakBot has placed its payload in hidden subdirectories.

T1566.002
Spearphishing Link
MalwareQakBot

QakBot has spread through emails with malicious links.

T1572
Protocol Tunneling
ToolBrute Ratel C4

Brute Ratel C4 can use DNS over HTTPS for C2.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.