Breitenbacher, D and Osis, K. (2020, June 17). OPERATION IN(TER)CEPTION: Targeted Attacks Against European Aerospace and Military Companies. Retrieved December 20, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.013 Encrypted/Encoded File |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group encrypted malware such as DRATzarus with XOR and DLL files with base64. |
| T1036.008 Masquerade File Type |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group disguised malicious template files as JPEG files to avoid detection. |
| T1047 Windows Management Instrumentation |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group used WMIC to executed a remote XSL script. |
| T1053.005 Scheduled Task |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group created scheduled tasks to set a periodic execution of a remote XSL script. |
| T1059.001 PowerShell |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group used PowerShell commands to explore the environment of compromised victims. |
| T1059.003 Windows Command Shell |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group launched malicious DLL files, created new folders, and renamed folders with the use of the Windows command shell. |
| T1070.004 File Deletion |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group removed all previously delivered files from a compromised computer. |
| T1087.002 Domain Account |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group queried compromised victim's active directory servers to obtain the list of employees including administrator accounts. |
| T1105 Ingress Tool Transfer |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group downloaded multistage malware and tools onto a compromised host. |
| T1110 Brute Force |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group performed brute force attacks against administrator accounts. |
| T1204.001 Malicious Link |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group lured users into executing a malicious link to disclose private account information or provide initial access. |
| T1218.010 Regsvr32 |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group used `regsvr32` to execute malware. |
| T1218.011 Rundll32 |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group executed malware with `C:\\windows\system32\rundll32.exe "C:\ProgramData\ThumbNail\thumbnail.db"`, `CtrlPanel S-6-81-3811-75432205-060098-6872 0 0 905`. |
| T1220 XSL Script Processing |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group used a remote XSL script to download a Base64-encoded DLL custom downloader. |
| T1553.002 Code Signing |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group digitally signed their own malware to evade detection. |
| T1560.001 Archive via Utility |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group archived victim's data into a RAR file. |
| T1566.002 Spearphishing Link |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group sent malicious OneDrive links with fictitious job offer advertisements via email. |
| T1566.003 Spearphishing via Service |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group sent victims spearphishing messages via LinkedIn concerning fictitious jobs. |
| T1567.002 Exfiltration to Cloud Storage |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group used a custom build of open-source command-line dbxcli to exfiltrate stolen data to Dropbox. |
| T1583.001 Domains |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group registered a domain name identical to that of a compromised company as part of their BEC effort. |
| T1583.004 Server |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group acquired servers to host their malicious tools. |
| T1584.004 Server |
CampaignOperation Dream Job | For Operation Dream Job, Lazarus Group compromised servers to host their malicious tools. |
| T1585.001 Social Media Accounts |
CampaignOperation Dream Job | For Operation Dream Job, Lazarus Group created fake LinkedIn accounts for their targeting efforts. |
| T1585.002 Email Accounts |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group created fake email accounts to correspond with fake LinkedIn personas; Lazarus Group also established email accounts to match those of the victim as part of their BEC attempt. |
| T1587.001 Malware |
CampaignOperation Dream Job | For Operation Dream Job, Lazarus Group developed custom tools such as Sumarta, DBLL Dropper, Torisma, and DRATzarus for their operations. |
| T1587.002 Code Signing Certificates |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group digitally signed their malware and the dbxcli utility. |
| T1588.002 Tool |
CampaignOperation Dream Job | For Operation Dream Job, Lazarus Group obtained tools such as Wake-On-Lan, Responder, ChromePass, and dbxcli. |
| T1588.003 Code Signing Certificates |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group used code signing certificates issued by Sectigo RSA for some of its malware and tools. |
| T1591.004 Identify Roles |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group targeted specific individuals within an organization with tailored job vacancy announcements. |
| T1593.001 Social Media |
CampaignOperation Dream Job | For Operation Dream Job, Lazarus Group used LinkedIn to identify and target employees within a chosen organization. |
| T1608.001 Upload Malware |
CampaignOperation Dream Job | For Operation Dream Job, Lazarus Group used compromised servers to host malware. |
| T1608.002 Upload Tool |
CampaignOperation Dream Job | For Operation Dream Job, Lazarus Group used multiple servers to host malicious tools. |
| T1684.001 Impersonation |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group impersonated HR hiring personnel through LinkedIn messages and conducted interviews with victims in order to deceive them into downloading malware. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.