ATT&CKReferencesMicrosoft SIR Vol 19

Microsoft SIR Vol 19

Anthe, C. et al. (2015, October 19). Microsoft Security Intelligence Report Volume 19. Retrieved December 23, 2015.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples15

TechniqueUsed byProcedure example
T1025
Data from Removable Media
GroupAPT28

An APT28 backdoor may collect the entire contents of an inserted USB device.

T1056.001
Keylogging
GroupAPT28

APT28 has used tools to perform keylogging.

T1068
Exploitation for Privilege Escalation
GroupAPT28

APT28 has exploited CVE-2014-4076, CVE-2015-2387, CVE-2015-1701, CVE-2017-0263, and CVE-2022-38028 to escalate privileges.

T1071.001
Web Protocols
MalwareCORESHELL

CORESHELL can communicate over HTTP for C2.

T1071.003
Mail Protocols
MalwareCORESHELL

CORESHELL can communicate over SMTP and POP3 for C2.

T1074.001
Local Data Staging
GroupAPT28

APT28 has stored captured credential information in a file named pi.log.

T1091
Replication Through Removable Media
GroupAPT28

APT28 uses a tool to infect connected USB devices and transmit itself to air-gapped computers when the infected USB device is inserted.

T1091
Replication Through Removable Media
MalwareCHOPSTICK

Part of APT28's operation involved using CHOPSTICK modules to copy itself to air-gapped machines and using files written to USB sticks to transfer data and command traffic.

T1092
Communication Through Removable Media
MalwareCHOPSTICK

Part of APT28's operation involved using CHOPSTICK modules to copy itself to air-gapped machines, using files written to USB sticks to transfer data and command traffic.

T1092
Communication Through Removable Media
GroupAPT28

APT28 uses a tool that captures information from air-gapped computers via an infected USB and transfers it to network-connected computer when the USB is inserted.

T1120
Peripheral Device Discovery
GroupAPT28

APT28 uses a module to receive a notification every time a USB mass storage device is inserted into a victim.

T1211
Exploitation for Stealth
GroupAPT28

APT28 has used CVE-2015-4902 to bypass security features.

T1218.011
Rundll32
MalwareCORESHELL

CORESHELL is installed via execution of rundll32 with an export named "init" or "InitW."

T1547.001
Registry Run Keys / Startup Folder
MalwareCORESHELL

CORESHELL has established persistence by creating autostart extensibility point (ASEP) Registry entries in the Run key and other Registry keys, as well as by creating shortcuts in the Internet Explorer Quick Start folder.

T1550.002
Pass the Hash
GroupAPT28

APT28 has used pass the hash for lateral movement.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.