CrowdStrike. (2022, January 27). Early Bird Catches the Wormhole: Observations from the StellarParticle Campaign. Retrieved February 7, 2022.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1001 Data Obfuscation |
MalwareTrailBlazer | TrailBlazer can masquerade its C2 traffic as legitimate Google Notifications HTTP requests. |
| T1001.001 Junk Data |
MalwareTrailBlazer | TrailBlazer has used random identifier strings to obscure its C2 operations and result codes. |
| T1003.006 DCSync |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used privileged accounts to replicate directory service data with domain controllers. |
| T1021.001 Remote Desktop Protocol |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used RDP sessions from public-facing systems to internal servers. |
| T1021.002 SMB/Windows Admin Shares |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used administrative accounts to connect over SMB to targeted users. |
| T1036 Masquerading |
MalwareTrailBlazer | TrailBlazer has used filenames that match the name of the compromised system in attempt to avoid detection. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareGoldMax | GoldMax has used filenames that matched the system name, and appeared as a scheduled task impersonating systems management software within the corresponding ProgramData subfolder. |
| T1053.003 Cron |
MalwareGoldMax | The GoldMax Linux variant has used a crontab entry with a |
| T1057 Process Discovery |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used multiple command-line utilities to enumerate running processes. |
| T1059.001 PowerShell |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used PowerShell to create new tasks on remote machines, identify configuration settings, exfiltrate data, and execute other commands. |
| T1069.002 Domain Groups |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used AdFind to enumerate domain groups. |
| T1071.001 Web Protocols |
MalwareTrailBlazer | TrailBlazer has used HTTP requests for C2. |
| T1078.002 Domain Accounts |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used domain administrators' accounts to help facilitate lateral movement on compromised networks. |
| T1078.003 Local Accounts |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used compromised local accounts to access victims' networks. |
| T1078.004 Cloud Accounts |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used a compromised O365 administrator account to create a new Service Principal. |
| T1087.002 Domain Account |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used PowerShell to discover domain accounts by exectuing `Get-ADUser` and `Get-ADGroupMember`. |
| T1090.001 Internal Proxy |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used SSH port forwarding capabilities on public-facing systems, and configured at least one instance of Cobalt Strike to use a network pipe over SMB. |
| T1098.001 Additional Cloud Credentials |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 added credentials to OAuth Applications and Service Principals. |
| T1098.003 Additional Cloud Roles |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 granted `company administrator` privileges to a newly created service principle. |
| T1133 External Remote Services |
CampaignSolarWinds Compromise | For the SolarWinds Compromise, APT29 used compromised identities to access networks via SSH, VPNs, and other remote access tools. |
| T1199 Trusted Relationship |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 gained access through compromised accounts at cloud solution partners, and used compromised certificates issued by Mimecast to authenticate to Mimecast customer systems. |
| T1213 Data from Information Repositories |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 accessed victims' internal knowledge repositories (wikis) to view sensitive corporate information on products, services, and internal business operations. |
| T1482 Domain Trust Discovery |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used the `Get-AcceptedDomain` PowerShell cmdlet to enumerate accepted domains through an Exchange Management Shell. They also used AdFind to enumerate domains and to discover trust between federated domains. |
| T1539 Steal Web Session Cookie |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 stole Chrome browser cookies by copying the Chrome profile directories of targeted users. |
| T1546.003 Windows Management Instrumentation Event Subscription |
MalwareTrailBlazer | TrailBlazer has the ability to use WMI for persistence. |
| T1550.001 Application Access Token |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used compromised service principals to make changes to the Office 365 environment. |
| T1550.004 Web Session Cookie |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used stolen cookies to access cloud resources and a forged `duo-sid` cookie to bypass MFA set on an email account. |
| T1555.003 Credentials from Web Browsers |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 stole users' saved passwords from Chrome. |
| T1560.001 Archive via Utility |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used 7-Zip to compress stolen emails into password-protected archives prior to exfltration; APT29 also compressed text files into zipped archives. |
| T1564.011 Ignore Process Interrupts |
MalwareGoldMax | The GoldMax Linux variant has been executed with the `nohup` command to ignore hangup signals and continue to run if the terminal session was terminated. |
| T1589.001 Credentials |
CampaignSolarWinds Compromise | For the SolarWinds Compromise, APT29 conducted credential theft operations to obtain credentials to be used for access to victim environments. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.