ATT&CKReferencesunit42_gamaredon_dec2022

unit42_gamaredon_dec2022

Unit 42. (2022, December 20). Russia’s Trident Ursa (aka Gamaredon APT) Cyber Conflict Operations Unwavering Since Invasion of Ukraine. Retrieved September 12, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples16

TechniqueUsed byProcedure example
T1001
Data Obfuscation
GroupGamaredon Group

Gamaredon Group has used obfuscated VBScripts with randomly generated variable names and concatenated strings.

T1047
Windows Management Instrumentation
GroupGamaredon Group

Gamaredon Group has used WMI to execute scripts used for discovery and for determining the C2 IP address. Gamaredon Group has used the following WMI query to search for a ping record: `Select * From Win32_PingStatus where Address = 'mil.gov.ua'`.

T1053.005
Scheduled Task
GroupGamaredon Group

Gamaredon Group has created scheduled tasks to launch executables after a designated number of minutes have passed.

T1071.001
Web Protocols
GroupGamaredon Group

Gamaredon Group has used HTTP and HTTPS for C2 communications.

T1102.003
One-Way Communication
GroupGamaredon Group

Gamaredon Group has used Telegram Messenger content to discover the IP address for C2 communications.

T1105
Ingress Tool Transfer
GroupGamaredon Group

Gamaredon Group has downloaded additional malware and tools onto a compromised host. For example, Gamaredon Group uses a backdoor script to retrieve and decode additional payloads once in victim environments.

T1140
Deobfuscate/Decode Files or Information
GroupGamaredon Group

Gamaredon Group tools decrypted additional payloads from the C2. Gamaredon Group has also decoded Base64-encoded source code of a downloader. Additionally, Gamaredon Group has decoded Telegram content to reveal the IP address for C2 communications.

T1204.001
Malicious Link
GroupGamaredon Group

Gamaredon Group has attempted to get users to click on a link pointing to a malicious HTML file leading to follow-on malicious content.

T1204.002
Malicious File
GroupGamaredon Group

Gamaredon Group has attempted to get users to click on Office attachments with malicious macros embedded. Gamaredon Group has also attempted to get users to click on thematically named files.

T1218.005
Mshta
GroupGamaredon Group

Gamaredon Group has used `mshta.exe` to execute malicious files.

T1480
Execution Guardrails
GroupGamaredon Group

Gamaredon Group has used geoblocking to limit downloads of the malicious file to specific geographic locations.

T1547.001
Registry Run Keys / Startup Folder
GroupGamaredon Group

Gamaredon Group tools have registered Run keys in the registry to give malicious VBS files persistence.

T1566.001
Spearphishing Attachment
GroupGamaredon Group

Gamaredon Group has delivered spearphishing emails with malicious attachments to targets. Additionally, Gamaredon Group has distributed malicious LNK files compressed in ZIP archives.

T1568.001
Fast Flux DNS
GroupGamaredon Group

Gamaredon Group has used fast flux DNS to mask their command and control channel behind rotating IP addresses. Additionally, Gamaredon Group has used a low-frequency variant of the single-flux method.

T1583.003
Virtual Private Server
GroupGamaredon Group

Gamaredon Group has used VPS hosting providers for infrastructure outside of Russia.

T1588.002
Tool
GroupGamaredon Group

Gamaredon Group has used various legitimate tools, such as `mshta.exe` and Reg, and services during operations.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.