Symantec. (2020, November 17). Japan-Linked Organizations Targeted in Long-Running and Sophisticated Attack Campaign. Retrieved December 17, 2020.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.003 NTDS |
GroupmenuPass | menuPass has used Ntdsutil to dump credentials. |
| T1005 Data from Local System |
GroupmenuPass | menuPass has collected various files from the compromised computers. |
| T1027.013 Encrypted/Encoded File |
GroupmenuPass | menuPass has encoded strings in its malware with base64 as well as with a simple, single-byte XOR obfuscation using key 0x40. |
| T1047 Windows Management Instrumentation |
GroupmenuPass | menuPass has used a modified version of pentesting script wmiexec.vbs, which logs into a remote machine using WMI. |
| T1059.001 PowerShell |
GroupmenuPass | menuPass uses PowerSploit to inject shellcode into PowerShell. |
| T1074.002 Remote Data Staging |
GroupmenuPass | menuPass has staged data on remote MSP systems or other victim networks prior to exfiltration. |
| T1078 Valid Accounts |
GroupmenuPass | menuPass has used valid accounts including shared between Managed Service Providers and clients to move between the two environments. |
| T1083 File and Directory Discovery |
GroupmenuPass | menuPass has searched compromised systems for folders of interest including those related to HR, audit and expense, and meeting memos. |
| T1106 Native API |
GroupmenuPass | menuPass has used native APIs including |
| T1119 Automated Collection |
GroupmenuPass | menuPass has used the Csvde tool to collect Active Directory files and data. |
| T1199 Trusted Relationship |
GroupmenuPass | menuPass has used legitimate access granted to Managed Service Providers in order to access victims of interest. |
| T1210 Exploitation of Remote Services |
GroupmenuPass | menuPass has used tools to exploit the ZeroLogon vulnerability (CVE-2020-1472). |
| T1560.001 Archive via Utility |
GroupmenuPass | menuPass has compressed files before exfiltration using TAR and RAR. |
| T1574.001 DLL |
GroupmenuPass | menuPass has used DLL side-loading to launch versions of Mimikatz and PwDump6 as well as UPPERCUT. menuPass has also used DLL search order hijacking. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.