ATT&CKReferencesMSTIC Nobelium Oct 2021

MSTIC Nobelium Oct 2021

Microsoft Threat Intelligence Center. (2021, October 25). NOBELIUM targeting delegated administrative privileges to facilitate broader attacks. Retrieved March 25, 2022.

Open the source

Techniques2

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples7

TechniqueUsed byProcedure example
T1087.004
Cloud Account
GroupAPT29

APT29 has conducted enumeration of Azure AD accounts.

T1090.003
Multi-hop Proxy
GroupAPT29

A backdoor used by APT29 created a Tor hidden service to forward traffic from the Tor client to local ports 3389 (RDP), 139 (Netbios), and 445 (SMB) enabling full remote access from outside the network and has also used TOR.

T1098.002
Additional Email Delegate Permissions
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 added their own devices as allowed IDs for active sync using `Set-CASMailbox`, allowing it to obtain copies of victim mailboxes. It also added additional permissions (such as Mail.Read and Mail.ReadWrite) to compromised Application or Service Principals.

T1110.003
Password Spraying
GroupAPT29

APT29 has conducted brute force password spray attacks.

T1136.003
Cloud Account
GroupAPT29

APT29 can create new users through Azure AD.

T1199
Trusted Relationship
GroupAPT29

APT29 has compromised IT, cloud services, and managed services providers to gain broad access to multiple customers for subsequent operations.

T1651
Cloud Administration Command
GroupAPT29

APT29 has used Azure Run Command and Azure Admin-on-Behalf-of (AOBO) to execute code on virtual machines.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.