ATT&CKReferencesAccenture Hogfish April 2018

Accenture Hogfish April 2018

Accenture Security. (2018, April 23). Hogfish Redleaves Campaign. Retrieved July 2, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples12

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
GroupmenuPass

menuPass has encoded strings in its malware with base64 as well as with a simple, single-byte XOR obfuscation using key 0x40.

T1055.012
Process Hollowing
GroupmenuPass

menuPass has used process hollowing in iexplore.exe to load the RedLeaves implant.

T1059.003
Windows Command Shell
GroupmenuPass

menuPass executes commands using a command-line interface and reverse shell. The group has used a modified version of pentesting script wmiexec.vbs to execute commands. menuPass has used malicious macros embedded inside Office documents to execute files.

T1070.004
File Deletion
GroupmenuPass

A menuPass macro deletes files after it has decoded and decompressed them.

T1071.001
Web Protocols
MalwareRedLeaves

RedLeaves can communicate to its C2 over HTTP and HTTPS if directed.

T1082
System Information Discovery
MalwareRedLeaves

RedLeaves can gather extended system information including the hostname, OS version number, platform, memory information, time elapsed since system startup, and CPU information.

T1113
Screen Capture
MalwareRedLeaves

RedLeaves can capture screenshots.

T1140
Deobfuscate/Decode Files or Information
GroupmenuPass

menuPass has used certutil in a macro to decode base64-encoded content contained in a dropper document attached to an email. The group has also used certutil -decode to decode files on the victim’s machine when dropping UPPERCUT.

T1204.002
Malicious File
GroupmenuPass

menuPass has attempted to get victims to open malicious files such as Windows Shortcuts (.lnk) and/or Microsoft Office documents, sent via email as part of spearphishing campaigns.

T1547.001
Registry Run Keys / Startup Folder
MalwareRedLeaves

RedLeaves attempts to add a shortcut file in the Startup folder to achieve persistence. If this fails, it attempts to add Registry Run keys.

T1547.009
Shortcut Modification
MalwareRedLeaves

RedLeaves attempts to add a shortcut file in the Startup folder to achieve persistence.

T1555.003
Credentials from Web Browsers
MalwareRedLeaves

RedLeaves can gather browser usernames and passwords.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.