ATT&CKReferencesVolexity PowerDuke November 2016

Volexity PowerDuke November 2016

Adair, S.. (2016, November 9). PowerDuke: Widespread Post-Election Spear Phishing Campaigns Targeting Think Tanks and NGOs. Retrieved January 11, 2017.

Open the source

Techniques2

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples15

TechniqueUsed byProcedure example
T1010
Application Window Discovery
MalwarePowerDuke

PowerDuke has a command to get text of the current foreground window.

T1016
System Network Configuration Discovery
MalwarePowerDuke

PowerDuke has a command to get the victim's domain and NetBIOS name.

T1027.003
Steganography
MalwarePowerDuke

PowerDuke uses steganography to hide backdoors in PNG files, which are also encrypted using the Tiny Encryption Algorithm (TEA).

T1033
System Owner/User Discovery
MalwarePowerDuke

PowerDuke has commands to get the current user's name and SID.

T1057
Process Discovery
MalwarePowerDuke

PowerDuke has a command to list the victim's processes.

T1059.003
Windows Command Shell
MalwarePowerDuke

PowerDuke runs cmd.exe /c and sends the output to its C2.

T1070.004
File Deletion
MalwarePowerDuke

PowerDuke has a command to write random data across a file and delete it.

T1082
System Information Discovery
MalwarePowerDuke

PowerDuke has commands to get information about the victim's name, build, version, serial number, and memory usage.

T1083
File and Directory Discovery
MalwarePowerDuke

PowerDuke has commands to get the current directory name as well as the size of a file. It also has commands to obtain information about logical drives, drive type, and free space.

T1105
Ingress Tool Transfer
MalwarePowerDuke

PowerDuke has a command to download a file.

T1124
System Time Discovery
MalwarePowerDuke

PowerDuke has commands to get the time the machine was built, the time, and the time zone.

T1218.011
Rundll32
MalwarePowerDuke

PowerDuke uses rundll32.exe to load.

T1485
Data Destruction
MalwarePowerDuke

PowerDuke has a command to write random data across a file and delete it.

T1547.001
Registry Run Keys / Startup Folder
MalwarePowerDuke

PowerDuke achieves persistence by using various Registry Run keys.

T1564.004
NTFS File Attributes
MalwarePowerDuke

PowerDuke hides many of its backdoor payloads in an alternate data stream (ADS).

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.