Glyer, C, et al. (2020, March). This Is Not a Test: APT41 Initiates Global Intrusion Campaign Using Multiple Exploits. Retrieved April 28, 2020.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027 Obfuscated Files or Information |
GroupAPT41 | APT41 used VMProtected binaries in multiple intrusions. |
| T1059.001 PowerShell |
GroupAPT41 | APT41 leveraged PowerShell to deploy malware families in victims’ environments. |
| T1059.003 Windows Command Shell |
GroupAPT41 | APT41 used |
| T1059.004 Unix Shell |
GroupAPT41 | APT41 used Linux shell commands for system survey and information gathering prior to exploitation of vulnerabilities such as CVE-2019-19871. |
| T1071.001 Web Protocols |
GroupAPT41 | APT41 used HTTP to download payloads for CVE-2019-19781 and CVE-2020-10189 exploits. |
| T1071.002 File Transfer Protocols |
GroupAPT41 | |
| T1083 File and Directory Discovery |
GroupAPT41 | APT41 has executed |
| T1104 Multi-Stage Channels |
GroupAPT41 | APT41 used the storescyncsvc.dll BEACON backdoor to download a secondary backdoor. |
| T1105 Ingress Tool Transfer |
GroupAPT41 | APT41 used certutil to download additional files. APT41 downloaded post-exploitation tools such as Cobalt Strike via command shell following initial access. APT41 has uploaded Procdump and NATBypass to a staging directory and has used these tools in follow-on activities. |
| T1190 Exploit Public-Facing Application |
GroupAPT41 | APT41 exploited CVE-2020-10189 against Zoho ManageEngine Desktop Central through unsafe deserialization, and CVE-2019-19781 to compromise Citrix Application Delivery Controllers (ADC) and gateway devices. APT41 leveraged vulnerabilities such as ProxyLogon exploitation or SQL injection for initial access. APT41 exploited CVE-2021-26855 against a vulnerable Microsoft Exchange Server to gain initial access to the victim network. |
| T1197 BITS Jobs |
GroupAPT41 | |
| T1543.003 Windows Service |
GroupAPT41 | APT41 modified legitimate Windows services to install malware backdoors. APT41 created the StorSyncSvc service to provide persistence for Cobalt Strike. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupAPT41 | APT41 created and modified startup files for persistence. APT41 added a registry key in |
| T1569.002 Service Execution |
GroupAPT41 | APT41 used svchost.exe and Net to execute a system service installed to launch a Cobalt Strike BEACON loader. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.