Novetta Threat Research Group. (2016, February 24). Operation Blockbuster: Remote Administration Tools & Content Staging Malware Report. Retrieved March 16, 2016.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
GroupLazarus Group | Lazarus Group has collected data and files from compromised networks. |
| T1008 Fallback Channels |
GroupLazarus Group | Lazarus Group malware SierraAlfa sends data to one of the hard-coded C2 servers chosen at random, and if the transmission fails, chooses a new C2 server to attempt the transmission again. |
| T1021.001 Remote Desktop Protocol |
GroupLazarus Group | Lazarus Group malware SierraCharlie uses RDP for propagation. |
| T1021.002 SMB/Windows Admin Shares |
GroupLazarus Group | Lazarus Group malware SierraAlfa accesses the |
| T1027.013 Encrypted/Encoded File |
GroupLazarus Group | Lazarus Group has used multiple types of encryption and encoding for their payloads, including AES, Caracachs, RC4, XOR, Base64, and other tricks such as creating aliases in code for Native API function names. |
| T1033 System Owner/User Discovery |
GroupLazarus Group | Various Lazarus Group malware enumerates logged-on users. |
| T1047 Windows Management Instrumentation |
GroupLazarus Group | Lazarus Group has used WMIC for discovery as well as to execute payloads for persistence and lateral movement. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
GroupLazarus Group | Lazarus Group malware SierraBravo-Two generates an email message via SMTP containing information about newly infected victims. |
| T1110.003 Password Spraying |
GroupLazarus Group | Lazarus Group malware attempts to connect to Windows shares for lateral movement by using a generated list of usernames, which center around permutations of the username Administrator, and weak passwords. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupLazarus Group | Lazarus Group has maintained persistence by loading malicious code into a startup folder or by adding a Registry Run key. |
| T1560 Archive Collected Data |
GroupLazarus Group | Lazarus Group has compressed exfiltrated data with RAR and used RomeoDelta malware to archive specified directories in .zip format, encrypt the .zip file, and upload it to C2. |
| T1560.002 Archive via Library |
GroupLazarus Group | Lazarus Group malware IndiaIndia saves information gathered about the victim to a file that is compressed with Zlib, encrypted, and uploaded to a C2 server. |
| T1560.003 Archive via Custom Method |
GroupLazarus Group | A Lazarus Group malware sample encrypts data using a simple byte based XOR operation prior to exfiltration. |
| T1571 Non-Standard Port |
GroupLazarus Group | Some Lazarus Group malware uses a list of ordered port numbers to choose a port for C2 traffic, creating port-protocol mismatches. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.