Cherepanov, A.. (2016, December 13). The rise of TeleBots: Analyzing disruptive KillDisk attacks. Retrieved June 10, 2020.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupSandworm Team | Sandworm Team has used its plainpwd tool, a modified version of Mimikatz, and comsvcs.dll to dump Windows credentials from system memory. |
| T1018 Remote System Discovery |
GroupSandworm Team | Sandworm Team has used a tool to query Active Directory using LDAP, discovering information about computers listed in AD. |
| T1027.010 Command Obfuscation |
GroupSandworm Team | Sandworm Team has used ROT13 encoding, AES encryption and compression with the zlib library for their Python-based backdoor. |
| T1036.004 Masquerade Task or Service |
MalwareKillDisk | KillDisk registers as a service under the Plug-And-Play Support name. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupSandworm Team | Sandworm Team has avoided detection by naming a malicious binary explorer.exe. |
| T1040 Network Sniffing |
GroupSandworm Team | Sandworm Team has used intercepter-NG to sniff passwords in network traffic. |
| T1041 Exfiltration Over C2 Channel |
GroupSandworm Team | Sandworm Team has sent system information to its C2 server using HTTP. |
| T1056.001 Keylogging |
GroupSandworm Team | Sandworm Team has used a keylogger to capture keystrokes by using the SetWindowsHookEx function. |
| T1059.005 Visual Basic |
GroupSandworm Team | Sandworm Team has created VBScripts to run an SSH server. |
| T1070.004 File Deletion |
MalwareKillDisk | KillDisk has the ability to quit and delete itself. |
| T1070.004 File Deletion |
GroupSandworm Team | Sandworm Team has used backdoors that can delete files used in an attack from an infected system. |
| T1071.001 Web Protocols |
GroupSandworm Team | Sandworm Team's BCS-server tool connects to the designated C2 server via HTTP. |
| T1087.002 Domain Account |
GroupSandworm Team | Sandworm Team has used a tool to query Active Directory using LDAP, discovering information about usernames listed in AD. |
| T1090 Proxy |
GroupSandworm Team | Sandworm Team's BCS-server tool can create an internal proxy server to redirect traffic from the adversary-controlled C2 to internal servers which may not be connected to the internet, but are interconnected locally. |
| T1102.002 Bidirectional Communication |
GroupSandworm Team | Sandworm Team has used the Telegram Bot API from Telegram Messenger to send and receive commands to its Python backdoor. Sandworm Team also used legitimate M.E.Doc software update check requests for sending and receiving commands and hosted malicious payloads on putdrive.com. |
| T1105 Ingress Tool Transfer |
GroupSandworm Team | Sandworm Team has pushed additional malicious tools onto an infected system to steal user credentials, move laterally, and destroy data. |
| T1132.001 Standard Encoding |
GroupSandworm Team | Sandworm Team's BCS-server tool uses base64 encoding and HTML tags for the communication traffic between the C2 server. |
| T1140 Deobfuscate/Decode Files or Information |
GroupSandworm Team | Sandworm Team's VBS backdoor can decode Base64-encoded data and save it to the %TEMP% folder. The group also decrypted received information using the Triple DES algorithm and decompresses it using GZip. |
| T1204.002 Malicious File |
GroupSandworm Team | Sandworm Team has tricked unwitting recipients into clicking on spearphishing attachments and enabling malicious macros embedded within files. |
| T1555.003 Credentials from Web Browsers |
GroupSandworm Team | Sandworm Team's CredRaptor tool can collect saved passwords from various internet browsers. |
| T1566.001 Spearphishing Attachment |
GroupSandworm Team | Sandworm Team has delivered malicious Microsoft Office and ZIP file attachments via spearphishing emails. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.