ATT&CKReferencesLunghi Iron Tiger Linux

Lunghi Iron Tiger Linux

Daniel Lunghi. (2023, March 1). Iron Tiger’s SysUpdate Reappears, Adds Linux Targeting. Retrieved March 20, 2023.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples24

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareSysUpdate

SysUpdate can collect information and files from a compromised host.

T1007
System Service Discovery
MalwareSysUpdate

SysUpdate can collect a list of services on a victim machine.

T1016
System Network Configuration Discovery
MalwareSysUpdate

SysUpdate can collected the IP address and domain name of a compromised host.

T1016.001
Internet Connection Discovery
MalwareSysUpdate

SysUpdate can contact the DNS server operated by Google as part of its C2 establishment process.

T1027.002
Software Packing
MalwareSysUpdate

SysUpdate has been packed with VMProtect.

T1033
System Owner/User Discovery
MalwareSysUpdate

SysUpdate can collect the username from a compromised host.

T1036.004
Masquerade Task or Service
MalwareSysUpdate

SysUpdate has named their unit configuration file similarly to other unit files residing in the same directory, `/usr/lib/systemd/system/`, to appear benign.

T1041
Exfiltration Over C2 Channel
MalwareSysUpdate

SysUpdate has exfiltrated data over its C2 channel.

T1057
Process Discovery
MalwareSysUpdate

SysUpdate can collect information about running processes.

T1071.004
DNS
MalwareSysUpdate

SysUpdate has used DNS TXT requests as for its C2 communication.

T1082
System Information Discovery
MalwareSysUpdate

SysUpdate can collect a system's architecture, operating system version, and hostname.

T1083
File and Directory Discovery
MalwareSysUpdate

SysUpdate can search files on a compromised host.

T1105
Ingress Tool Transfer
MalwareSysUpdate

SysUpdate has the ability to download files to a compromised host.

T1106
Native API
MalwareSysUpdate

SysUpdate can call the `GetNetworkParams` API as part of its C2 establishment process.

T1132.001
Standard Encoding
MalwareSysUpdate

SysUpdate has used Base64 to encode its C2 traffic.

T1543.002
Systemd Service
MalwareSysUpdate

SysUpdate can copy a script to the user owned `/usr/lib/systemd/system/` directory with a symlink mapped to a `root` owned directory, `/etc/ystem/system`, in the unit configuration file's `ExecStart` directive to establish persistence and elevate privileges.

T1543.003
Windows Service
GroupThreat Group-3390

Threat Group-3390's malware can create a new service, sometimes naming it after the config information, to gain persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupThreat Group-3390

Threat Group-3390's malware can add a Registry key to `Software\Microsoft\Windows\CurrentVersion\Run` for persistence.

T1553.002
Code Signing
MalwareSysUpdate

SysUpdate has been signed with stolen digital certificates.

T1573.001
Symmetric Cryptography
MalwareSysUpdate

SysUpdate has used DES to encrypt all C2 communications.

T1574.001
DLL
GroupThreat Group-3390

Threat Group-3390 has performed DLL search order hijacking to execute their payload. Threat Group-3390 has also used DLL side-loading, including by using legitimate Kaspersky antivirus variants as well as `rc.exe`, a legitimate Microsoft Resource Compiler.

T1583.001
Domains
GroupThreat Group-3390

Threat Group-3390 has registered domains for C2.

T1588.003
Code Signing Certificates
GroupThreat Group-3390

Threat Group-3390 has obtained stolen valid certificates, including from VMProtect and the Chinese instant messaging application Youdu, for their operations.

T1680
Local Storage Discovery
MalwareSysUpdate

SysUpdate can collect a system's drive information.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.