Nikita Rostovcev. (2022, August 18). APT41 World Tour 2021 on a tight schedule. Retrieved February 22, 2024.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.002 Security Account Manager |
GroupAPT41 | APT41 extracted user account data from the Security Account Managerr (SAM), making a copy of this database from the registry using the |
| T1003.003 NTDS |
GroupAPT41 | APT41 used ntdsutil to obtain a copy of the victim environment |
| T1012 Query Registry |
GroupAPT41 | APT41 queried registry values to determine items such as configured RDP ports and network configurations. |
| T1027.002 Software Packing |
GroupAPT41 | APT41 uses packers such as Themida to obfuscate malicious files. |
| T1030 Data Transfer Size Limits |
GroupAPT41 | APT41 transfers post-exploitation files dividing the payload into fixed-size chunks to evade detection. |
| T1033 System Owner/User Discovery |
GroupAPT41 | APT41 has executed |
| T1069 Permission Groups Discovery |
GroupAPT41 | APT41 used |
| T1070.004 File Deletion |
GroupAPT41 | APT41 deleted files from the system. |
| T1082 System Information Discovery |
GroupAPT41 | APT41 uses multiple built-in commands such as |
| T1087.001 Local Account |
GroupAPT41 | APT41 used built-in |
| T1087.002 Domain Account |
GroupAPT41 | APT41 used built-in |
| T1105 Ingress Tool Transfer |
GroupAPT41 | APT41 used certutil to download additional files. APT41 downloaded post-exploitation tools such as Cobalt Strike via command shell following initial access. APT41 has uploaded Procdump and NATBypass to a staging directory and has used these tools in follow-on activities. |
| T1190 Exploit Public-Facing Application |
GroupAPT41 | APT41 exploited CVE-2020-10189 against Zoho ManageEngine Desktop Central through unsafe deserialization, and CVE-2019-19781 to compromise Citrix Application Delivery Controllers (ADC) and gateway devices. APT41 leveraged vulnerabilities such as ProxyLogon exploitation or SQL injection for initial access. APT41 exploited CVE-2021-26855 against a vulnerable Microsoft Exchange Server to gain initial access to the victim network. |
| T1213.003 Code Repositories |
GroupAPT41 | APT41 cloned victim user Git repositories during intrusions. |
| T1550.002 Pass the Hash |
GroupAPT41 | APT41 uses tools such as Mimikatz to enable lateral movement via captured password hashes. |
| T1555 Credentials from Password Stores |
GroupAPT41 | APT41 has obtained information about accounts, lists of employees, and plaintext and hashed passwords from databases. |
| T1555.003 Credentials from Web Browsers |
GroupAPT41 | APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores. |
| T1570 Lateral Tool Transfer |
GroupAPT41 | APT41 uses remote shares to move and remotely execute payloads during lateral movemement. |
| T1595.002 Vulnerability Scanning |
GroupAPT41 | APT41 used the Acunetix SQL injection vulnerability scanner in target reconnaissance operations, as well as the JexBoss tool to identify vulnerabilities in Java applications. |
| T1595.003 Wordlist Scanning |
GroupAPT41 | APT41 leverages various tools and frameworks to brute-force directories on web servers. |
| T1596.005 Scan Databases |
GroupAPT41 | APT41 uses the Chinese website fofa.su, similar to the Shodan scanning service, for passive scanning of victims. |
| T1685 Disable or Modify Tools |
GroupAPT41 | APT41 developed a custom injector that enables an Event Tracing for Windows (ETW) bypass, making malicious processes invisible to Windows logging. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.