Global Threat Center, Intelligence Team. (2020, December). APT27 Turns to Ransomware. Retrieved November 12, 2021.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareRCSession | RCSession can collect data from a compromised host. |
| T1027.011 Fileless Storage |
MalwareRCSession | RCSession can store its obfuscated configuration file in the Registry under `HKLM\SOFTWARE\Plus` or `HKCU\SOFTWARE\Plus`. |
| T1033 System Owner/User Discovery |
MalwareRCSession | RCSession can gather system owner information, including user and administrator privileges. |
| T1055.012 Process Hollowing |
MalwareRCSession | RCSession can launch itself from a hollowed svchost.exe process. |
| T1056.001 Keylogging |
MalwareRCSession | RCSession has the ability to capture keystrokes on a compromised host. |
| T1057 Process Discovery |
MalwareRCSession | RCSession can identify processes based on PID. |
| T1068 Exploitation for Privilege Escalation |
GroupThreat Group-3390 | Threat Group-3390 has used CVE-2014-6324 and CVE-2017-0213 to escalate privileges. |
| T1070.004 File Deletion |
MalwareRCSession | RCSession can remove files from a targeted system. |
| T1071.001 Web Protocols |
MalwareRCSession | RCSession can use HTTP in C2 communications. |
| T1082 System Information Discovery |
MalwareRCSession | RCSession can gather system information from a compromised host. |
| T1095 Non-Application Layer Protocol |
MalwareRCSession | RCSession has the ability to use TCP and UDP in C2 communications. |
| T1105 Ingress Tool Transfer |
MalwareRCSession | RCSession has the ability to drop additional files to an infected machine. |
| T1106 Native API |
MalwareRCSession | RCSession can use WinSock API for communication including |
| T1112 Modify Registry |
MalwareRCSession | RCSession can write its configuration file to the Registry. |
| T1113 Screen Capture |
MalwareRCSession | RCSession can capture screenshots from a compromised host. |
| T1199 Trusted Relationship |
GroupThreat Group-3390 | Threat Group-3390 has compromised third party service providers to gain access to victim's environments. |
| T1218.007 Msiexec |
MalwareRCSession | RCSession has the ability to execute inside the msiexec.exe process. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareRCSession | RCSession has the ability to modify a Registry Run key to establish persistence. |
| T1574.001 DLL |
MalwarePlugX | PlugX has the ability to use DLL search order hijacking for installation on targeted systems. PlugX has also used DLL side-loading to evade anti-virus. PlugX has also used a legitimately signed executable to side-load a malicious payload within a DLL file. Cisco Talos MUSTANG PANDA PLUGX PUBLOAD MAY 2022Dell TG-3390EclecticIQ Mustang Panda PlugXEset PlugX Korplug Mustang Panda March 2022FireEye Clandestine Fox Part 2PWC Cloud Hopper Technical Annex April 2017Palo Alto PlugX June 2017Profero APT27 December 2020Proofpoint TA416 Europe March 2022Sophos Mustang Panda PLUGXSophos PlugX September 2022Stewart 2014Trend Micro DRBControl February 2020 |
| T1574.001 DLL |
MalwareRCSession | RCSession can be installed via DLL side-loading. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.