ATT&CKReferencesCheck Point Sunburst Teardrop December 2020

Check Point Sunburst Teardrop December 2020

Check Point Research. (2020, December 22). SUNBURST, TEARDROP and the NetSec New Normal. Retrieved January 6, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples4

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
MalwareTEARDROP

TEARDROP created and read from a file with a fake JPG header, and its payload was encrypted with a simple rotating XOR cipher.

T1112
Modify Registry
MalwareTEARDROP

TEARDROP modified the Registry to create a Windows service for itself on a compromised host.

T1140
Deobfuscate/Decode Files or Information
MalwareTEARDROP

TEARDROP was decoded using a custom rolling XOR algorithm to execute a customized Cobalt Strike payload.

T1543.003
Windows Service
MalwareTEARDROP

TEARDROP ran as a Windows service from the c:\windows\syswow64 folder.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.