ATT&CKReferencesKaspersky ProjectSauron Full Report

Kaspersky ProjectSauron Full Report

Kaspersky Lab's Global Research & Analysis Team. (2016, August 9). The ProjectSauron APT. Retrieved August 17, 2016.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples12

TechniqueUsed byProcedure example
T1036.005
Match Legitimate Resource Name or Location
MalwareRemsec

The Remsec loader implements itself with the name Security Support Provider, a legitimate Windows function. Various Remsec .exe files mimic legitimate file names used by Microsoft, Symantec, Kaspersky, Hewlett-Packard, and VMWare. Remsec also disguised malicious modules using similar filenames as custom network encryption software on victims.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwareRemsec

Remsec can exfiltrate data via a DNS tunnel or email, separately from its C2 channel.

T1052.001
Exfiltration over USB
MalwareRemsec

Remsec contains a module to move data from airgapped networks to Internet-connected systems by using a removable USB device.

T1070.004
File Deletion
MalwareRemsec

Remsec is capable of deleting files on the victim. It also securely removes itself after collecting and exfiltrating data.

T1071.001
Web Protocols
MalwareRemsec

Remsec is capable of using HTTP and HTTPS for C2.

T1071.003
Mail Protocols
MalwareRemsec

Remsec is capable of using SMTP for C2.

T1071.004
DNS
MalwareRemsec

Remsec is capable of using DNS for C2.

T1083
File and Directory Discovery
MalwareRemsec

Remsec is capable of listing contents of folders on the victim. Remsec also searches for custom network encryption software on victims.

T1095
Non-Application Layer Protocol
MalwareRemsec

Remsec is capable of using ICMP, TCP, and UDP for C2.

T1556.002
Password Filter DLL
GroupStrider

Strider has registered its persistence module on domain controllers as a Windows LSA (Local System Authority) password filter to acquire credentials any time a domain, local user, or administrator logs in or changes a password.

T1556.002
Password Filter DLL
MalwareRemsec

Remsec harvests plain-text credentials as a password filter registered on domain controllers.

T1564.005
Hidden File System
GroupStrider

Strider has used a hidden file system that is stored as a file on disk.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.