Kenefick, I. et al. (2022, October 12). Black Basta Ransomware Gang Infiltrates Networks via QAKBOT, Brute Ratel, and Cobalt Strike. Retrieved February 6, 2023.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareQakBot | QakBot can use |
| T1018 Remote System Discovery |
MalwareQakBot | QakBot can identify remote systems through the |
| T1021.002 SMB/Windows Admin Shares |
MalwareCobalt Strike | Cobalt Strike can use Window admin shares (C$ and ADMIN$) for lateral movement. |
| T1027.006 HTML Smuggling |
MalwareQakBot | QakBot has been delivered in ZIP files via HTML smuggling. |
| T1027.010 Command Obfuscation |
MalwareQakBot | QakBot can use obfuscated and encoded scripts. |
| T1033 System Owner/User Discovery |
MalwareQakBot | QakBot can identify the user name on a compromised system. |
| T1036.008 Masquerade File Type |
MalwareQakBot | The QakBot payload has been disguised as a PNG file and hidden within LNK files using a Microsoft File Explorer icon. |
| T1049 System Network Connections Discovery |
MalwareQakBot | QakBot can use |
| T1055 Process Injection |
MalwareQakBot | QakBot can inject itself into processes including explore.exe, Iexplore.exe, Mobsync.exe., and wermgr.exe. |
| T1059.003 Windows Command Shell |
MalwareQakBot | QakBot can use cmd.exe to launch itself and to execute multiple C2 commands. |
| T1059.003 Windows Command Shell |
MalwareCobalt Strike | Cobalt Strike uses a command-line interface to interact with systems. |
| T1059.005 Visual Basic |
MalwareQakBot | QakBot can use VBS to download and execute malicious files. |
| T1059.007 JavaScript |
MalwareQakBot | The QakBot web inject module can inject Java Script into web banking pages visited by the victim. |
| T1069.001 Local Groups |
MalwareQakBot | QakBot can use |
| T1069.002 Domain Groups |
ToolBrute Ratel C4 | Brute Ratel C4 can use `net group` for discovery on targeted domains. |
| T1071.001 Web Protocols |
ToolBrute Ratel C4 | Brute Ratel C4 can use HTTPS and HTTPS for C2 communication. |
| T1071.004 DNS |
ToolBrute Ratel C4 | Brute Ratel C4 can use DNS over HTTPS for C2. |
| T1087.002 Domain Account |
ToolBrute Ratel C4 | Brute Ratel C4 can use LDAP queries, `net group "Domain Admins" /domain` and `net user /domain` for discovery. |
| T1204.001 Malicious Link |
MalwareQakBot | QakBot has gained execution through users opening malicious links. |
| T1218.010 Regsvr32 |
MalwareQakBot | QakBot can use Regsvr32 to execute malicious DLLs. |
| T1218.011 Rundll32 |
MalwareQakBot | QakBot has used Rundll32.exe to drop malicious DLLs including Brute Ratel C4 and to enable C2 communication. |
| T1218.011 Rundll32 |
MalwareCobalt Strike | Cobalt Strike can use `rundll32.exe` to load DLL from the command line. |
| T1482 Domain Trust Discovery |
ToolBrute Ratel C4 | Brute Ratel C4 can use LDAP queries and `nltest /domain_trusts` for domain trust discovery. |
| T1553.005 Mark-of-the-Web Bypass |
MalwareQakBot | QakBot has been packaged in ISO files in order to bypass Mark of the Web (MOTW) security measures. |
| T1560 Archive Collected Data |
ToolBloodHound | BloodHound can compress data collected by its SharpHound ingestor into a ZIP file to be written to disk. |
| T1564.001 Hidden Files and Directories |
MalwareQakBot | QakBot has placed its payload in hidden subdirectories. |
| T1566.002 Spearphishing Link |
MalwareQakBot | QakBot has spread through emails with malicious links. |
| T1572 Protocol Tunneling |
ToolBrute Ratel C4 | Brute Ratel C4 can use DNS over HTTPS for C2. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.