Accenture Security. (2018, April 23). Hogfish Redleaves Campaign. Retrieved July 2, 2018.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.013 Encrypted/Encoded File |
GroupmenuPass | menuPass has encoded strings in its malware with base64 as well as with a simple, single-byte XOR obfuscation using key 0x40. |
| T1055.012 Process Hollowing |
GroupmenuPass | menuPass has used process hollowing in iexplore.exe to load the RedLeaves implant. |
| T1059.003 Windows Command Shell |
GroupmenuPass | menuPass executes commands using a command-line interface and reverse shell. The group has used a modified version of pentesting script wmiexec.vbs to execute commands. menuPass has used malicious macros embedded inside Office documents to execute files. |
| T1070.004 File Deletion |
GroupmenuPass | A menuPass macro deletes files after it has decoded and decompressed them. |
| T1071.001 Web Protocols |
MalwareRedLeaves | RedLeaves can communicate to its C2 over HTTP and HTTPS if directed. |
| T1082 System Information Discovery |
MalwareRedLeaves | RedLeaves can gather extended system information including the hostname, OS version number, platform, memory information, time elapsed since system startup, and CPU information. |
| T1113 Screen Capture |
MalwareRedLeaves | RedLeaves can capture screenshots. |
| T1140 Deobfuscate/Decode Files or Information |
GroupmenuPass | menuPass has used certutil in a macro to decode base64-encoded content contained in a dropper document attached to an email. The group has also used |
| T1204.002 Malicious File |
GroupmenuPass | menuPass has attempted to get victims to open malicious files such as Windows Shortcuts (.lnk) and/or Microsoft Office documents, sent via email as part of spearphishing campaigns. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareRedLeaves | RedLeaves attempts to add a shortcut file in the Startup folder to achieve persistence. If this fails, it attempts to add Registry Run keys. |
| T1547.009 Shortcut Modification |
MalwareRedLeaves | RedLeaves attempts to add a shortcut file in the Startup folder to achieve persistence. |
| T1555.003 Credentials from Web Browsers |
MalwareRedLeaves | RedLeaves can gather browser usernames and passwords. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.