ATT&CKReferencesCrowdStrike StellarParticle January 2022

CrowdStrike StellarParticle January 2022

CrowdStrike. (2022, January 27). Early Bird Catches the Wormhole: Observations from the StellarParticle Campaign. Retrieved February 7, 2022.

Open the source

Techniques2

Groups0

None recorded.

Software2

Campaigns1

Procedure examples31

TechniqueUsed byProcedure example
T1001
Data Obfuscation
MalwareTrailBlazer

TrailBlazer can masquerade its C2 traffic as legitimate Google Notifications HTTP requests.

T1001.001
Junk Data
MalwareTrailBlazer

TrailBlazer has used random identifier strings to obscure its C2 operations and result codes.

T1003.006
DCSync
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used privileged accounts to replicate directory service data with domain controllers.

T1021.001
Remote Desktop Protocol
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used RDP sessions from public-facing systems to internal servers.

T1021.002
SMB/Windows Admin Shares
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used administrative accounts to connect over SMB to targeted users.

T1036
Masquerading
MalwareTrailBlazer

TrailBlazer has used filenames that match the name of the compromised system in attempt to avoid detection.

T1036.005
Match Legitimate Resource Name or Location
MalwareGoldMax

GoldMax has used filenames that matched the system name, and appeared as a scheduled task impersonating systems management software within the corresponding ProgramData subfolder.

T1053.003
Cron
MalwareGoldMax

The GoldMax Linux variant has used a crontab entry with a @reboot line to gain persistence.

T1057
Process Discovery
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used multiple command-line utilities to enumerate running processes.

T1059.001
PowerShell
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used PowerShell to create new tasks on remote machines, identify configuration settings, exfiltrate data, and execute other commands.

T1069.002
Domain Groups
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used AdFind to enumerate domain groups.

T1071.001
Web Protocols
MalwareTrailBlazer

TrailBlazer has used HTTP requests for C2.

T1078.002
Domain Accounts
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used domain administrators' accounts to help facilitate lateral movement on compromised networks.

T1078.003
Local Accounts
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used compromised local accounts to access victims' networks.

T1078.004
Cloud Accounts
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used a compromised O365 administrator account to create a new Service Principal.

T1087.002
Domain Account
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used PowerShell to discover domain accounts by exectuing `Get-ADUser` and `Get-ADGroupMember`.

T1090.001
Internal Proxy
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used SSH port forwarding capabilities on public-facing systems, and configured at least one instance of Cobalt Strike to use a network pipe over SMB.

T1098.001
Additional Cloud Credentials
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 added credentials to OAuth Applications and Service Principals.

T1098.003
Additional Cloud Roles
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 granted `company administrator` privileges to a newly created service principle.

T1133
External Remote Services
CampaignSolarWinds Compromise

For the SolarWinds Compromise, APT29 used compromised identities to access networks via SSH, VPNs, and other remote access tools.

T1199
Trusted Relationship
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 gained access through compromised accounts at cloud solution partners, and used compromised certificates issued by Mimecast to authenticate to Mimecast customer systems.

T1213
Data from Information Repositories
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 accessed victims' internal knowledge repositories (wikis) to view sensitive corporate information on products, services, and internal business operations.

T1482
Domain Trust Discovery
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used the `Get-AcceptedDomain` PowerShell cmdlet to enumerate accepted domains through an Exchange Management Shell. They also used AdFind to enumerate domains and to discover trust between federated domains.

T1539
Steal Web Session Cookie
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 stole Chrome browser cookies by copying the Chrome profile directories of targeted users.

T1546.003
Windows Management Instrumentation Event Subscription
MalwareTrailBlazer

TrailBlazer has the ability to use WMI for persistence.

T1550.001
Application Access Token
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used compromised service principals to make changes to the Office 365 environment.

T1550.004
Web Session Cookie
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used stolen cookies to access cloud resources and a forged `duo-sid` cookie to bypass MFA set on an email account.

T1555.003
Credentials from Web Browsers
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 stole users' saved passwords from Chrome.

T1560.001
Archive via Utility
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used 7-Zip to compress stolen emails into password-protected archives prior to exfltration; APT29 also compressed text files into zipped archives.

T1564.011
Ignore Process Interrupts
MalwareGoldMax

The GoldMax Linux variant has been executed with the `nohup` command to ignore hangup signals and continue to run if the terminal session was terminated.

T1589.001
Credentials
CampaignSolarWinds Compromise

For the SolarWinds Compromise, APT29 conducted credential theft operations to obtain credentials to be used for access to victim environments.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.