ATT&CKReferencesKISA Operation Muzabi

KISA Operation Muzabi

KISA. (2021). Phishing Target Reconnaissance and Attack Resource Analysis Operation Muzabi. Retrieved March 8, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples44

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupKimsuky

Kimsuky has gathered credentials using Mimikatz and ProcDump.

T1005
Data from Local System
MalwareAppleSeed

AppleSeed can collect data on a compromised host.

T1025
Data from Removable Media
MalwareAppleSeed

AppleSeed can find and collect data from removable media devices.

T1030
Data Transfer Size Limits
MalwareAppleSeed

AppleSeed has divided files if the size is 0x1000000 bytes or more.

T1053.005
Scheduled Task
GroupKimsuky

Kimsuky has downloaded additional malware with scheduled tasks. Kimsuky has established persistence by creating a scheduled task named “ChromeUpdateTaskMachine” through the PowerShell cmdlet `Register-ScheduleTask` which was set to execute another PowerShell script once, then five minutes after its creation and periodically repeat every 30 minutes. Kimsuky has also set scheduled tasks that run periodically using the PT1M repetition pattern leveraging naming conventions of Anti-Virus software to include "AhnlabUpdate".

T1056.001
Keylogging
MalwareAppleSeed

AppleSeed can use GetKeyState and GetKeyboardState to capture keystrokes on the victim’s machine.

T1056.001
Keylogging
GroupKimsuky

Kimsuky has used a PowerShell-based keylogger as well as a tool called MECHANICAL to log keystrokes. Kimsuky has also leveraged Native Windows API functions such as `GetAsyncKeyState()` along with others to capture keystrokes every 50 milliseconds and stores data in a file stored in the temp directory.

T1059.001
PowerShell
GroupKimsuky

Kimsuky has executed a variety of PowerShell scripts including Invoke-Mimikatz. Kimsuky has also utilized PowerShell scripts for execution, persistence, and defense evasion. Kimsuky has leveraged PowerShell’s cmdlet `Expand-Archive` to extract contents of zip files into the same directory. Kimsuky has employed ClickFix type tactics enticing victims to copy and paste malicious PowerShell commands and scripts, where the scripts ultimately led to QuasarRAT.

T1059.003
Windows Command Shell
GroupKimsuky

Kimsuky has executed Windows commands by using `cmd` and running batch scripts. Kimsuky has also used `cmd.exe` to automatically open downloaded decoy pdf documents with the system’s default PDF viewer. Kimsuky has utilized malicious payloads to create reverse shells within the victim environment. Kimsuky has also used batch scripts to eventually run QuasarRAT.

T1059.006
Python
GroupKimsuky

Kimsuky has used a macOS Python implant to gather data as well as MailFetcher.py code to automatically collect email data.

T1070.004
File Deletion
GroupKimsuky

Kimsuky has deleted the exfiltrated data on disk after transmission. Kimsuky has also used an instrumentor script to terminate browser processes running on an infected system and then delete the cookie files on disk. Kimsuky has deleted files using the `Remove-Item` PowerShell commandlet to remove traces of executed payloads. Kimsuky has also removed remnants of files used for delivery to include .log and .zip files.

T1071.001
Web Protocols
MalwareAppleSeed

AppleSeed has the ability to communicate with C2 over HTTP.

T1083
File and Directory Discovery
GroupKimsuky

Kimsuky has the ability to enumerate all files and directories on an infected system. Kimsuky has used a custom script with a function called CreateFileList() that can scan all filesystem drives, prioritizing C:\Users, to locate files and file extensions of interest that ultimately generates a file called `FileList.txt` saved within the victims %TEMP% Directory that contains the findings and the respective pathways.

T1098.007
Additional Local or Domain Groups
GroupKimsuky

Kimsuky has added accounts to specific groups with net localgroup.

T1111
Multi-Factor Authentication Interception
GroupKimsuky

Kimsuky has used a proprietary tool to intercept one time passwords required for two-factor authentication.

T1112
Modify Registry
GroupKimsuky

Kimsuky has modified Registry settings for default file associations to enable all macros and for persistence. Kimsuky has also modified the registry entry for `HKCU:\Software\Microsoft\Windows\CurrentVersion\Run` registry key for persistence with the name WindowsSecurityCheck.

T1113
Screen Capture
MalwareAppleSeed

AppleSeed can take screenshots on a compromised host by calling a series of APIs.

T1114.002
Remote Email Collection
GroupKimsuky

Kimsuky has used tools such as the MailFetch mail crawler to collect victim emails (excluding spam) from online services via IMAP.

T1119
Automated Collection
MalwareAppleSeed

AppleSeed has automatically collected data from USB drives, keystrokes, and screen images before exfiltration.

T1136.001
Local Account
GroupKimsuky

Kimsuky has created accounts with net user.

T1190
Exploit Public-Facing Application
GroupKimsuky

Kimsuky has exploited various vulnerabilities for initial access, including Microsoft Exchange vulnerability CVE-2020-0688.

T1204.001
Malicious Link
GroupKimsuky

Kimsuky has lured victims into clicking malicious links.

T1218.005
Mshta
GroupKimsuky

Kimsuky has used mshta.exe to run malicious scripts on the system.

T1218.010
Regsvr32
GroupKimsuky

Kimsuky has executed malware with regsvr32s.

T1518.001
Security Software Discovery
GroupKimsuky

Kimsuky has checked for the presence of antivirus software with powershell Get-CimInstance -Namespace root/securityCenter2 – classname antivirusproduct. Kimsuky has also obtained details on antivirus software through WMI queries using `Win32_OperatingSystem` and `SecurityCenter2.AntiVirusProduct`. Kimsuky has also checked the status of Windows Defender through the use `cmd /s sc query WinDefend`.

T1534
Internal Spearphishing
GroupKimsuky

Kimsuky has sent internal spearphishing emails for lateral movement after stealing victim information.

T1547.001
Registry Run Keys / Startup Folder
GroupKimsuky

Kimsuky has placed scripts in the startup folder for persistence and modified the `HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce` Registry key.

T1560
Archive Collected Data
MalwareAppleSeed

AppleSeed has compressed collected data before exfiltration.

T1564.002
Hidden Users
GroupKimsuky

Kimsuky has run reg add ‘HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList’ /v to hide a newly created user.

T1566.001
Spearphishing Attachment
GroupKimsuky

Kimsuky has used emails containing Word, Excel and/or HWP (Hangul Word Processor) documents in their spearphishing campaigns. Kimsuky has also distributed emails with attached compressed zip files that contained malicious .LNK files masquerading as legitimate files. Kimsuky has delivered tailored PDF documents that contain malicious links.

T1566.002
Spearphishing Link
GroupKimsuky

Kimsuky has sent spearphishing emails containing a link to a document that contained malicious macros or took the victim to an actor-controlled domain.

T1567
Exfiltration Over Web Service
MalwareAppleSeed

AppleSeed has exfiltrated files using web services.

T1583.001
Domains
GroupKimsuky

Kimsuky has registered domains to spoof targeted organizations and trusted third parties including search engines, web platforms, and cryptocurrency exchanges.

T1583.004
Server
GroupKimsuky

Kimsuky has purchased hosting servers with virtual currency and prepaid cards.

T1584.001
Domains
GroupKimsuky

Kimsuky has compromised legitimate sites and used them to distribute malware.

T1585.001
Social Media Accounts
GroupKimsuky

Kimsuky has created social media accounts to monitor news and security trends as well as potential targets.

T1585.002
Email Accounts
GroupKimsuky

Kimsuky has created email accounts for phishing operations.

T1587.001
Malware
GroupKimsuky

Kimsuky has developed its own unique malware such as MailFetch.py for use in operations.

T1588.005
Exploits
GroupKimsuky

Kimsuky has obtained exploit code for various CVEs.

T1589.003
Employee Names
GroupKimsuky

Kimsuky has collected victim employee name information.

T1591
Gather Victim Org Information
GroupKimsuky

Kimsuky has collected victim organization information including but not limited to organization hierarchy, functions, press releases, and others. Kimsuky has also used large language models (LLMs) to gather information about potential targets of interest.

T1593.002
Search Engines
GroupKimsuky

Kimsuky has searched for vulnerabilities, tools, and geopolitical trends on Google to target victims.

T1594
Search Victim-Owned Websites
GroupKimsuky

Kimsuky has searched for information on the target company's website.

T1598.003
Spearphishing Link
GroupKimsuky

Kimsuky has used links in e-mail to steal account information including web beacons for target profiling. Kimsuky has also utilized QR codes (also known as Quishing) to direct victims to malicious links through the reliance of a mobile device to scan a code with an embedded malicious URL.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.