ATT&CKReferencesProfero APT27 December 2020

Profero APT27 December 2020

Global Threat Center, Intelligence Team. (2020, December). APT27 Turns to Ransomware. Retrieved November 12, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples20

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareRCSession

RCSession can collect data from a compromised host.

T1027.011
Fileless Storage
MalwareRCSession

RCSession can store its obfuscated configuration file in the Registry under `HKLM\SOFTWARE\Plus` or `HKCU\SOFTWARE\Plus`.

T1033
System Owner/User Discovery
MalwareRCSession

RCSession can gather system owner information, including user and administrator privileges.

T1055.012
Process Hollowing
MalwareRCSession

RCSession can launch itself from a hollowed svchost.exe process.

T1056.001
Keylogging
MalwareRCSession

RCSession has the ability to capture keystrokes on a compromised host.

T1057
Process Discovery
MalwareRCSession

RCSession can identify processes based on PID.

T1068
Exploitation for Privilege Escalation
GroupThreat Group-3390

Threat Group-3390 has used CVE-2014-6324 and CVE-2017-0213 to escalate privileges.

T1070.004
File Deletion
MalwareRCSession

RCSession can remove files from a targeted system.

T1071.001
Web Protocols
MalwareRCSession

RCSession can use HTTP in C2 communications.

T1082
System Information Discovery
MalwareRCSession

RCSession can gather system information from a compromised host.

T1095
Non-Application Layer Protocol
MalwareRCSession

RCSession has the ability to use TCP and UDP in C2 communications.

T1105
Ingress Tool Transfer
MalwareRCSession

RCSession has the ability to drop additional files to an infected machine.

T1106
Native API
MalwareRCSession

RCSession can use WinSock API for communication including WSASend and WSARecv.

T1112
Modify Registry
MalwareRCSession

RCSession can write its configuration file to the Registry.

T1113
Screen Capture
MalwareRCSession

RCSession can capture screenshots from a compromised host.

T1199
Trusted Relationship
GroupThreat Group-3390

Threat Group-3390 has compromised third party service providers to gain access to victim's environments.

T1218.007
Msiexec
MalwareRCSession

RCSession has the ability to execute inside the msiexec.exe process.

T1547.001
Registry Run Keys / Startup Folder
MalwareRCSession

RCSession has the ability to modify a Registry Run key to establish persistence.

T1574.001
DLL
MalwarePlugX

PlugX has the ability to use DLL search order hijacking for installation on targeted systems. PlugX has also used DLL side-loading to evade anti-virus. PlugX has also used a legitimately signed executable to side-load a malicious payload within a DLL file.

T1574.001
DLL
MalwareRCSession

RCSession can be installed via DLL side-loading.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.