ATT&CKReferencesProofpoint TA416 Europe March 2022

Proofpoint TA416 Europe March 2022

Raggi, M. et al. (2022, March 7). The Good, the Bad, and the Web Bug: TA416 Increases Operational Tempo Against European Governments as Conflict in Ukraine Escalates. Retrieved March 16, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples18

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
GroupMustang Panda

Mustang Panda has delivered initial payloads hidden using archives and encoding measures. Mustang Panda has also utilized opaque predicates in payloads to hinder analysis.

T1027
Obfuscated Files or Information
MalwarePlugX

PlugX can use API hashing and modify the names of strings to evade detection.

T1036.005
Match Legitimate Resource Name or Location
MalwarePlugX

PlugX has been disguised as legitimate Adobe and PotPlayer files. PlugX has also imitated legitimate software directories and file names through the creation and storage of a legitimate EXE and the malicious DLLs.

T1071.001
Web Protocols
MalwarePlugX

PlugX can be configured to use HTTP for command and control. PlugX has also used HTTPS for C2.

T1083
File and Directory Discovery
MalwarePlugX

PlugX has a module to enumerate drives and find files recursively. PlugX has also checked the path from which it is running for specific parameters prior to execution.

T1102
Web Service
GroupMustang Panda

Mustang Panda has used DropBox URLs to deliver variants of PlugX. Mustang Panda has also used Google Drive to host malicious downloads.

T1105
Ingress Tool Transfer
MalwarePlugX

PlugX has a module to download and execute files on the compromised machine.

T1106
Native API
MalwarePlugX

PlugX can use the Windows API functions `GetProcAddress`, `LoadLibrary`, and `CreateProcess` to execute another process.

T1140
Deobfuscate/Decode Files or Information
MalwarePlugX

PlugX decompresses and decrypts itself using the Microsoft API call RtlDecompressBuffer. PlugX has also decrypted its payloads in memory.

T1204.001
Malicious Link
GroupMustang Panda

Mustang Panda has sent malicious links including links directing victims to a Google Drive folder. Mustang Panda has also utilized webpages with Javascript code that downloads malicious payloads to the victim device.

T1204.002
Malicious File
GroupMustang Panda

Mustang Panda has sent malicious files requiring direct victim interaction to execute. Mustang Panda has also leveraged executable files that display decoy documents to the victim to provide a resemblance of legitimacy with customized themes related to the victim.

T1564.001
Hidden Files and Directories
MalwarePlugX

PlugX can modify the characteristics of folders to hide them from the compromised user. PlugX has also modified file attributes to hidden and system.

T1573.001
Symmetric Cryptography
MalwarePlugX

PlugX can use RC4 encryption in C2 communications.

T1574.001
DLL
MalwarePlugX

PlugX has the ability to use DLL search order hijacking for installation on targeted systems. PlugX has also used DLL side-loading to evade anti-virus. PlugX has also used a legitimately signed executable to side-load a malicious payload within a DLL file.

T1585.002
Email Accounts
GroupMustang Panda

Mustang Panda has leveraged the legitimate email marketing service SMTP2Go for phishing campaigns. Mustang Panda has also created fake Google accounts to distribute malware via spear-phishing emails. Mustang Panda has also created accounts for spearphishing operations including the use of services such as Proton Mail.

T1598.003
Spearphishing Link
GroupMustang Panda

Mustang Panda has delivered web bugs to profile their intended targets.

T1608
Stage Capabilities
GroupMustang Panda

Mustang Panda has used servers under their control to validate tracking pixels sent to phishing victims.

T1608.001
Upload Malware
GroupMustang Panda

Mustang Panda has hosted malicious payloads on DropBox including PlugX.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.