ATT&CKReferencesFireEye KEGTAP SINGLEMALT October 2020

FireEye KEGTAP SINGLEMALT October 2020

Kimberly Goody, Jeremy Kennelly, Joshua Shilko, Steve Elovitz, Douglas Bienstock. (2020, October 28). Unhappy Hour Special: KEGTAP and SINGLEMALT With a Ransomware Chaser. Retrieved October 28, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples16

TechniqueUsed byProcedure example
T1003.002
Security Account Manager
GroupWizard Spider

Wizard Spider has acquired credentials from the SAM/SECURITY registry hives.

T1003.003
NTDS
GroupWizard Spider

Wizard Spider has gained access to credentials via exported copies of the ntds.dit Active Directory database. Wizard Spider has also created a volume shadow copy and used a batch script file to collect NTDS.dit with the use of the Windows utility, ntdsutil.

T1018
Remote System Discovery
GroupWizard Spider

Wizard Spider has used networkdll for network discovery and psfin specifically for financial and point of sale indicators. Wizard Spider has also used AdFind, nltest/dclist, and PowerShell script Get-DataInfo.ps1 to enumerate domain computers, including the domain controller.

T1036.004
Masquerade Task or Service
GroupWizard Spider

Wizard Spider has used scheduled tasks to install TrickBot, using task names to appear legitimate such as WinDotNet, GoogleTask, or Sysnetsf. It has also used common document file names for other malware binaries.

T1047
Windows Management Instrumentation
GroupWizard Spider

Wizard Spider has used WMI and LDAP queries for network discovery and to move laterally. Wizard Spider has also used batch scripts to leverage WMIC to deploy ransomware.

T1053.005
Scheduled Task
GroupWizard Spider

Wizard Spider has used scheduled tasks to establish persistence for TrickBot and other malware.

T1059.001
PowerShell
GroupWizard Spider

Wizard Spider has used macros to execute PowerShell scripts to download malware on victim's machines. It has also used PowerShell to execute commands and move laterally through a victim network.

T1078.002
Domain Accounts
GroupWizard Spider

Wizard Spider has used administrative accounts, including Domain Admin, to move laterally within a victim network.

T1133
External Remote Services
GroupWizard Spider

Wizard Spider has accessed victim networks by using stolen credentials to access the corporate VPN infrastructure.

T1210
Exploitation of Remote Services
GroupWizard Spider

Wizard Spider has exploited or attempted to exploit Zerologon (CVE-2020-1472) and EternalBlue (MS17-010) vulnerabilities.

T1547.001
Registry Run Keys / Startup Folder
GroupWizard Spider

Wizard Spider has established persistence via the Registry key HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run and a shortcut within the startup folder.

T1547.004
Winlogon Helper DLL
GroupWizard Spider

Wizard Spider has established persistence using Userinit by adding the Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon.

T1557.001
Name Resolution Poisoning and SMB Relay
GroupWizard Spider

Wizard Spider has used the Invoke-Inveigh PowerShell cmdlets, likely for name service poisoning.

T1558.003
Kerberoasting
GroupWizard Spider

Wizard Spider has used Rubeus, MimiKatz Kerberos module, and the Invoke-Kerberoast cmdlet to steal AES hashes.

T1588.002
Tool
GroupWizard Spider

Wizard Spider has utilized tools such as Empire, Cobalt Strike, Cobalt Strike, Rubeus, AdFind, BloodHound, Metasploit, Advanced IP Scanner, Nirsoft PingInfoView, and SoftPerfect Network Scanner for targeting efforts.

T1685
Disable or Modify Tools
GroupWizard Spider

Wizard Spider has shut down or uninstalled security applications on victim systems that might prevent ransomware from executing.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.