ATT&CKReferencesRewterz Sidewinder COVID-19 June 2020

Rewterz Sidewinder COVID-19 June 2020

Rewterz. (2020, June 22). Analysis on Sidewinder APT Group – COVID-19. Retrieved January 29, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples9

TechniqueUsed byProcedure example
T1036.005
Match Legitimate Resource Name or Location
GroupSidewinder

Sidewinder has named malicious files rekeywiz.exe to match the name of a legitimate Windows executable.

T1059.007
JavaScript
GroupSidewinder

Sidewinder has used JavaScript to drop and execute malware loaders.

T1071.001
Web Protocols
GroupSidewinder

Sidewinder has used HTTP in C2 communications.

T1082
System Information Discovery
GroupSidewinder

Sidewinder has used tools to collect the computer name, OS version, installed hotfixes, as well as information regarding the memory and processor on a compromised host.

T1204.001
Malicious Link
GroupSidewinder

Sidewinder has lured targets to click on malicious links to gain execution in the target environment.

T1204.002
Malicious File
GroupSidewinder

Sidewinder has lured targets to click on malicious files to gain execution in the target environment.

T1218.005
Mshta
GroupSidewinder

Sidewinder has used mshta.exe to execute malicious payloads.

T1547.001
Registry Run Keys / Startup Folder
GroupSidewinder

Sidewinder has added paths to executables in the Registry to establish persistence.

T1559.002
Dynamic Data Exchange
GroupSidewinder

Sidewinder has used the ActiveXObject utility to create OLE objects to obtain execution through Internet Explorer.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.