Unit 42. (2022, February 3). Russia’s Gamaredon aka Primitive Bear APT Group Actively Targeting Ukraine. Retrieved February 21, 2022.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1021.005 VNC |
GroupGamaredon Group | Gamaredon Group has used VNC tools, including UltraVNC, to remotely interact with compromised hosts. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupGamaredon Group | Gamaredon Group has used legitimate process names to hide malware including |
| T1057 Process Discovery |
GroupGamaredon Group | Gamaredon Group has used tools to enumerate processes on target hosts including Process Explorer. |
| T1059.003 Windows Command Shell |
GroupGamaredon Group | Gamaredon Group has used various batch scripts to establish C2 and download additional files. Gamaredon Group's backdoor malware has also been written to a batch file. |
| T1071.001 Web Protocols |
GroupGamaredon Group | Gamaredon Group has used HTTP and HTTPS for C2 communications. |
| T1083 File and Directory Discovery |
GroupGamaredon Group | Gamaredon Group macros can scan for Microsoft Word and Excel files to inject with additional malicious macros. Gamaredon Group has also used its backdoors to automatically list interesting files (such as Office documents) found on a system. Gamaredon Group has also identified directory trees, folders and files on the compromised host. |
| T1105 Ingress Tool Transfer |
MalwarePteranodon | Pteranodon can download and execute additional files. |
| T1113 Screen Capture |
MalwarePteranodon | Pteranodon can capture screenshots at a configurable interval. |
| T1204.002 Malicious File |
GroupGamaredon Group | Gamaredon Group has attempted to get users to click on Office attachments with malicious macros embedded. Gamaredon Group has also attempted to get users to click on thematically named files. |
| T1221 Template Injection |
GroupGamaredon Group | Gamaredon Group has used DOCX files to download malicious DOT document templates and has used RTF template injection to download malicious payloads. Gamaredon Group can also inject malicious macros or remote templates into documents already present on compromised systems. |
| T1497 Virtualization/Sandbox Evasion |
MalwarePteranodon | Pteranodon has the ability to use anti-detection functions to identify sandbox environments. |
| T1564.003 Hidden Window |
GroupGamaredon Group | Gamaredon Group has used |
| T1566.001 Spearphishing Attachment |
GroupGamaredon Group | Gamaredon Group has delivered spearphishing emails with malicious attachments to targets. Additionally, Gamaredon Group has distributed malicious LNK files compressed in ZIP archives. |
| T1568 Dynamic Resolution |
GroupGamaredon Group | Gamaredon Group has incorporated dynamic DNS domains in its infrastructure. |
| T1583.001 Domains |
GroupGamaredon Group | Gamaredon Group has registered multiple domains to facilitate payload staging and C2. |
| T1608.001 Upload Malware |
GroupGamaredon Group | Gamaredon Group has registered domains to stage payloads. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.