Kaspersky Lab's Global Research & Analysis Team. (2016, August 9). The ProjectSauron APT. Retrieved August 17, 2016.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1036.005 Match Legitimate Resource Name or Location |
MalwareRemsec | The Remsec loader implements itself with the name Security Support Provider, a legitimate Windows function. Various Remsec .exe files mimic legitimate file names used by Microsoft, Symantec, Kaspersky, Hewlett-Packard, and VMWare. Remsec also disguised malicious modules using similar filenames as custom network encryption software on victims. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareRemsec | Remsec can exfiltrate data via a DNS tunnel or email, separately from its C2 channel. |
| T1052.001 Exfiltration over USB |
MalwareRemsec | Remsec contains a module to move data from airgapped networks to Internet-connected systems by using a removable USB device. |
| T1070.004 File Deletion |
MalwareRemsec | Remsec is capable of deleting files on the victim. It also securely removes itself after collecting and exfiltrating data. |
| T1071.001 Web Protocols |
MalwareRemsec | Remsec is capable of using HTTP and HTTPS for C2. |
| T1071.003 Mail Protocols |
MalwareRemsec | Remsec is capable of using SMTP for C2. |
| T1071.004 DNS |
MalwareRemsec | Remsec is capable of using DNS for C2. |
| T1083 File and Directory Discovery |
MalwareRemsec | Remsec is capable of listing contents of folders on the victim. Remsec also searches for custom network encryption software on victims. |
| T1095 Non-Application Layer Protocol |
MalwareRemsec | Remsec is capable of using ICMP, TCP, and UDP for C2. |
| T1556.002 Password Filter DLL |
GroupStrider | Strider has registered its persistence module on domain controllers as a Windows LSA (Local System Authority) password filter to acquire credentials any time a domain, local user, or administrator logs in or changes a password. |
| T1556.002 Password Filter DLL |
MalwareRemsec | Remsec harvests plain-text credentials as a password filter registered on domain controllers. |
| T1564.005 Hidden File System |
GroupStrider | Strider has used a hidden file system that is stored as a file on disk. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.