ATT&CKReferencesFireEye APT41 March 2020

FireEye APT41 March 2020

Glyer, C, et al. (2020, March). This Is Not a Test: APT41 Initiates Global Intrusion Campaign Using Multiple Exploits. Retrieved April 28, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples14

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
GroupAPT41

APT41 used VMProtected binaries in multiple intrusions.

T1059.001
PowerShell
GroupAPT41

APT41 leveraged PowerShell to deploy malware families in victims’ environments.

T1059.003
Windows Command Shell
GroupAPT41

APT41 used cmd.exe /c to execute commands on remote machines.
APT41 used a batch file to install persistence for the Cobalt Strike BEACON loader.

T1059.004
Unix Shell
GroupAPT41

APT41 used Linux shell commands for system survey and information gathering prior to exploitation of vulnerabilities such as CVE-2019-19871.

T1071.001
Web Protocols
GroupAPT41

APT41 used HTTP to download payloads for CVE-2019-19781 and CVE-2020-10189 exploits.

T1071.002
File Transfer Protocols
GroupAPT41

APT41 used exploit payloads that initiate download via ftp.

T1083
File and Directory Discovery
GroupAPT41

APT41 has executed file /bin/pwd on exploited victims, perhaps to return architecture related information.

T1104
Multi-Stage Channels
GroupAPT41

APT41 used the storescyncsvc.dll BEACON backdoor to download a secondary backdoor.

T1105
Ingress Tool Transfer
GroupAPT41

APT41 used certutil to download additional files. APT41 downloaded post-exploitation tools such as Cobalt Strike via command shell following initial access. APT41 has uploaded Procdump and NATBypass to a staging directory and has used these tools in follow-on activities.

T1190
Exploit Public-Facing Application
GroupAPT41

APT41 exploited CVE-2020-10189 against Zoho ManageEngine Desktop Central through unsafe deserialization, and CVE-2019-19781 to compromise Citrix Application Delivery Controllers (ADC) and gateway devices. APT41 leveraged vulnerabilities such as ProxyLogon exploitation or SQL injection for initial access. APT41 exploited CVE-2021-26855 against a vulnerable Microsoft Exchange Server to gain initial access to the victim network.

T1197
BITS Jobs
GroupAPT41

APT41 used BITSAdmin to download and install payloads.

T1543.003
Windows Service
GroupAPT41

APT41 modified legitimate Windows services to install malware backdoors. APT41 created the StorSyncSvc service to provide persistence for Cobalt Strike.

T1547.001
Registry Run Keys / Startup Folder
GroupAPT41

APT41 created and modified startup files for persistence. APT41 added a registry key in HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost to establish persistence for Cobalt Strike.

T1569.002
Service Execution
GroupAPT41

APT41 used svchost.exe and Net to execute a system service installed to launch a Cobalt Strike BEACON loader.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.