Douglas Bienstock. (2022, August 18). You Can’t Audit Me: APT29 Continues Targeting Microsoft 365. Retrieved February 23, 2023.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1036.005 Match Legitimate Resource Name or Location |
GroupAPT29 | APT29 has renamed malicious DLLs with legitimate names to appear benign; they have also created an Azure AD certificate with a Common Name that matched the display name of the compromised service principal. |
| T1078 Valid Accounts |
GroupAPT29 | APT29 has used a compromised account to access an organization's VPN infrastructure. |
| T1078.004 Cloud Accounts |
GroupAPT29 | APT29 has gained access to a global administrator account in Azure AD and has used `Service Principal` credentials in Exchange. |
| T1098.002 Additional Email Delegate Permissions |
GroupAPT29 | APT29 has used a compromised global administrator account in Azure AD to backdoor a service principal with `ApplicationImpersonation` rights to start collecting emails from targeted mailboxes; APT29 has also used compromised accounts holding `ApplicationImpersonation` rights in Exchange to collect emails. |
| T1098.005 Device Registration |
GroupAPT29 | APT29 has enrolled their own devices into compromised cloud tenants, including enrolling a device in MFA to an Azure AD environment following a successful password guessing attack against a dormant account. |
| T1110.001 Password Guessing |
GroupAPT29 | APT29 has successfully conducted password guessing attacks against a list of mailboxes. |
| T1114.002 Remote Email Collection |
GroupAPT29 | APT29 has collected emails from targeted mailboxes within a compromised Azure AD tenant and compromised Exchange servers, including via Exchange Web Services (EWS) API requests. |
| T1133 External Remote Services |
GroupAPT29 | APT29 has used compromised identities to access networks via VPNs and Citrix. |
| T1586.002 Email Accounts |
GroupAPT29 | APT29 has compromised email accounts to further enable phishing campaigns and taken control of dormant accounts. |
| T1586.003 Cloud Accounts |
GroupAPT29 | APT29 has used residential proxies, including Azure Virtual Machines, to obfuscate their access to victim environments. |
| T1685.002 Disable or Modify Cloud Log |
GroupAPT29 | APT29 has disabled Purview Audit on targeted accounts prior to stealing emails from Microsoft 365 tenants. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.