ATT&CKReferencesESET LightNeuron May 2019

ESET LightNeuron May 2019

Faou, M. (2019, May). Turla LightNeuron: One email away from remote code execution. Retrieved June 24, 2019.

Open the source

Techniques1

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples22

TechniqueUsed byProcedure example
T1001.002
Steganography
MalwareLightNeuron

LightNeuron is controlled via commands that are embedded into PDFs and JPGs using steganographic methods.

T1005
Data from Local System
MalwareLightNeuron

LightNeuron can collect files from a local system.

T1016
System Network Configuration Discovery
MalwareLightNeuron

LightNeuron gathers information about network adapters using the Win32 API call GetAdaptersInfo.

T1020
Automated Exfiltration
MalwareLightNeuron

LightNeuron can be configured to automatically exfiltrate files under a specified directory.

T1027.013
Encrypted/Encoded File
MalwareLightNeuron

LightNeuron encrypts its configuration files with AES-256.

T1029
Scheduled Transfer
MalwareLightNeuron

LightNeuron can be configured to exfiltrate data during nighttime or working hours.

T1036.005
Match Legitimate Resource Name or Location
MalwareLightNeuron

LightNeuron has used filenames associated with Exchange and Outlook for binary and configuration files, such as winmail.dat.

T1041
Exfiltration Over C2 Channel
MalwareLightNeuron

LightNeuron exfiltrates data over its email C2 channel.

T1059.003
Windows Command Shell
MalwareLightNeuron

LightNeuron is capable of executing commands via cmd.exe.

T1070.004
File Deletion
MalwareLightNeuron

LightNeuron has a function to delete files.

T1071.003
Mail Protocols
MalwareLightNeuron

LightNeuron uses SMTP for C2.

T1074.001
Local Data Staging
MalwareLightNeuron

LightNeuron can store email data in files and directories specified in its configuration, such as C:\Windows\ServiceProfiles\NetworkService\appdata\Local\Temp\.

T1082
System Information Discovery
MalwareLightNeuron

LightNeuron gathers the victim computer name using the Win32 API call GetComputerName.

T1105
Ingress Tool Transfer
MalwareLightNeuron

LightNeuron has the ability to download and execute additional files.

T1106
Native API
MalwareLightNeuron

LightNeuron is capable of starting a process using CreateProcess.

T1114.002
Remote Email Collection
MalwareLightNeuron

LightNeuron collects Exchange emails matching rules specified in its configuration.

T1119
Automated Collection
MalwareLightNeuron

LightNeuron can be configured to automatically collect files under a specified directory.

T1140
Deobfuscate/Decode Files or Information
MalwareLightNeuron

LightNeuron has used AES and XOR to decrypt configuration files and commands.

T1505.002
Transport Agent
MalwareLightNeuron

LightNeuron has used a malicious Microsoft Exchange transport agent for persistence.

T1560
Archive Collected Data
MalwareLightNeuron

LightNeuron contains a function to encrypt and store emails that it collects.

T1565.002
Transmitted Data Manipulation
MalwareLightNeuron

LightNeuron is capable of modifying email content, headers, and attachments during transit.

T1573.001
Symmetric Cryptography
MalwareLightNeuron

LightNeuron uses AES to encrypt C2 traffic.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.