ATT&CKReferencesMandiant APT29 Microsoft 365 2022

Mandiant APT29 Microsoft 365 2022

Douglas Bienstock. (2022, August 18). You Can’t Audit Me: APT29 Continues Targeting Microsoft 365. Retrieved February 23, 2023.

Open the source

Techniques2

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples11

TechniqueUsed byProcedure example
T1036.005
Match Legitimate Resource Name or Location
GroupAPT29

APT29 has renamed malicious DLLs with legitimate names to appear benign; they have also created an Azure AD certificate with a Common Name that matched the display name of the compromised service principal.

T1078
Valid Accounts
GroupAPT29

APT29 has used a compromised account to access an organization's VPN infrastructure.

T1078.004
Cloud Accounts
GroupAPT29

APT29 has gained access to a global administrator account in Azure AD and has used `Service Principal` credentials in Exchange.

T1098.002
Additional Email Delegate Permissions
GroupAPT29

APT29 has used a compromised global administrator account in Azure AD to backdoor a service principal with `ApplicationImpersonation` rights to start collecting emails from targeted mailboxes; APT29 has also used compromised accounts holding `ApplicationImpersonation` rights in Exchange to collect emails.

T1098.005
Device Registration
GroupAPT29

APT29 has enrolled their own devices into compromised cloud tenants, including enrolling a device in MFA to an Azure AD environment following a successful password guessing attack against a dormant account.

T1110.001
Password Guessing
GroupAPT29

APT29 has successfully conducted password guessing attacks against a list of mailboxes.

T1114.002
Remote Email Collection
GroupAPT29

APT29 has collected emails from targeted mailboxes within a compromised Azure AD tenant and compromised Exchange servers, including via Exchange Web Services (EWS) API requests.

T1133
External Remote Services
GroupAPT29

APT29 has used compromised identities to access networks via VPNs and Citrix.

T1586.002
Email Accounts
GroupAPT29

APT29 has compromised email accounts to further enable phishing campaigns and taken control of dormant accounts.

T1586.003
Cloud Accounts
GroupAPT29

APT29 has used residential proxies, including Azure Virtual Machines, to obfuscate their access to victim environments.

T1685.002
Disable or Modify Cloud Log
GroupAPT29

APT29 has disabled Purview Audit on targeted accounts prior to stealing emails from Microsoft 365 tenants.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.