ATT&CKReferencesUnit 42 Gamaredon February 2022

Unit 42 Gamaredon February 2022

Unit 42. (2022, February 3). Russia’s Gamaredon aka Primitive Bear APT Group Actively Targeting Ukraine. Retrieved February 21, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples16

TechniqueUsed byProcedure example
T1021.005
VNC
GroupGamaredon Group

Gamaredon Group has used VNC tools, including UltraVNC, to remotely interact with compromised hosts.

T1036.005
Match Legitimate Resource Name or Location
GroupGamaredon Group

Gamaredon Group has used legitimate process names to hide malware including svchosst. Additionally, Gamaredon Group disguised malicious ZIP archives as Office documents that are related to the invasion.

T1057
Process Discovery
GroupGamaredon Group

Gamaredon Group has used tools to enumerate processes on target hosts including Process Explorer.

T1059.003
Windows Command Shell
GroupGamaredon Group

Gamaredon Group has used various batch scripts to establish C2 and download additional files. Gamaredon Group's backdoor malware has also been written to a batch file.

T1071.001
Web Protocols
GroupGamaredon Group

Gamaredon Group has used HTTP and HTTPS for C2 communications.

T1083
File and Directory Discovery
GroupGamaredon Group

Gamaredon Group macros can scan for Microsoft Word and Excel files to inject with additional malicious macros. Gamaredon Group has also used its backdoors to automatically list interesting files (such as Office documents) found on a system. Gamaredon Group has also identified directory trees, folders and files on the compromised host.

T1105
Ingress Tool Transfer
MalwarePteranodon

Pteranodon can download and execute additional files.

T1113
Screen Capture
MalwarePteranodon

Pteranodon can capture screenshots at a configurable interval.

T1204.002
Malicious File
GroupGamaredon Group

Gamaredon Group has attempted to get users to click on Office attachments with malicious macros embedded. Gamaredon Group has also attempted to get users to click on thematically named files.

T1221
Template Injection
GroupGamaredon Group

Gamaredon Group has used DOCX files to download malicious DOT document templates and has used RTF template injection to download malicious payloads. Gamaredon Group can also inject malicious macros or remote templates into documents already present on compromised systems.

T1497
Virtualization/Sandbox Evasion
MalwarePteranodon

Pteranodon has the ability to use anti-detection functions to identify sandbox environments.

T1564.003
Hidden Window
GroupGamaredon Group

Gamaredon Group has used hidcon to run batch files in a hidden console window. Gamaredon Group has also executed PowerShell in a hidden window.

T1566.001
Spearphishing Attachment
GroupGamaredon Group

Gamaredon Group has delivered spearphishing emails with malicious attachments to targets. Additionally, Gamaredon Group has distributed malicious LNK files compressed in ZIP archives.

T1568
Dynamic Resolution
GroupGamaredon Group

Gamaredon Group has incorporated dynamic DNS domains in its infrastructure.

T1583.001
Domains
GroupGamaredon Group

Gamaredon Group has registered multiple domains to facilitate payload staging and C2.

T1608.001
Upload Malware
GroupGamaredon Group

Gamaredon Group has registered domains to stage payloads.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.