ATT&CKReferencesKaspersky Sofacy

Kaspersky Sofacy

Kaspersky Lab's Global Research and Analysis Team. (2015, December 4). Sofacy APT hits high profile targets with updated toolset. Retrieved December 10, 2015.

Open the source

Techniques2

Groups0

None recorded.

Software3

Campaigns0

None recorded.

Procedure examples7

TechniqueUsed byProcedure example
T1025
Data from Removable Media
MalwareUSBStealer

Once a removable media device is inserted back into the first victim, USBStealer collects data from it that was exfiltrated from a second victim.

T1027
Obfuscated Files or Information
MalwareADVSTORESHELL

Most of the strings in ADVSTORESHELL are encrypted with an XOR-based algorithm; some strings are also encrypted with 3DES and reversed. API function names are also reversed, presumably to avoid detection in memory.

T1071.001
Web Protocols
MalwareADVSTORESHELL

ADVSTORESHELL connects to port 80 of a C2 server using Wininet API. Data is exchanged via HTTP POSTs.

T1074.001
Local Data Staging
MalwareUSBStealer

USBStealer collects files matching certain criteria from the victim and stores them in a local directory for later exfiltration.

T1083
File and Directory Discovery
MalwareUSBStealer

USBStealer searches victim drives for files matching certain extensions (“.skr”,“.pkr” or “.key”) or names.

T1132.001
Standard Encoding
MalwareADVSTORESHELL

C2 traffic from ADVSTORESHELL is encrypted, then encoded with Base64 encoding.

T1547.001
Registry Run Keys / Startup Folder
MalwareADVSTORESHELL

ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.