ATT&CKReferencesNccgroup Emissary Panda May 2018

Nccgroup Emissary Panda May 2018

Pantazopoulos, N., Henry T. (2018, May 18). Emissary Panda – A potential new malicious tool. Retrieved June 25, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples11

TechniqueUsed byProcedure example
T1012
Query Registry
GroupThreat Group-3390

A Threat Group-3390 tool can read and decrypt stored Registry values.

T1018
Remote System Discovery
GroupThreat Group-3390

Threat Group-3390 has used the net view command.

T1027.013
Encrypted/Encoded File
GroupThreat Group-3390

A Threat Group-3390 tool can encrypt payloads using XOR. Threat Group-3390 malware is also obfuscated using Metasploit’s shikata_ga_nai encoder.

T1027.015
Compression
GroupThreat Group-3390

Threat Group-3390 malware is compressed with LZNT1 compression.

T1047
Windows Management Instrumentation
GroupThreat Group-3390

A Threat Group-3390 tool can use WMI to execute a binary.

T1055.012
Process Hollowing
GroupThreat Group-3390

A Threat Group-3390 tool can spawn `svchost.exe` and inject the payload into that process.

T1112
Modify Registry
GroupThreat Group-3390

A Threat Group-3390 tool has created new Registry keys under `HKEY_CURRENT_USER\Software\Classes\` and `HKLM\SYSTEM\CurrentControlSet\services`.

T1543.003
Windows Service
GroupThreat Group-3390

Threat Group-3390's malware can create a new service, sometimes naming it after the config information, to gain persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupThreat Group-3390

Threat Group-3390's malware can add a Registry key to `Software\Microsoft\Windows\CurrentVersion\Run` for persistence.

T1548.002
Bypass User Account Control
GroupThreat Group-3390

A Threat Group-3390 tool can use a public UAC bypass method to elevate privileges.

T1574.001
DLL
GroupThreat Group-3390

Threat Group-3390 has performed DLL search order hijacking to execute their payload. Threat Group-3390 has also used DLL side-loading, including by using legitimate Kaspersky antivirus variants as well as `rc.exe`, a legitimate Microsoft Resource Compiler.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.