FireEye. (2015). APT28: A WINDOW INTO RUSSIA’S CYBER ESPIONAGE OPERATIONS?. Retrieved August 19, 2015.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1001.001 Junk Data |
GroupAPT28 | APT28 added "junk data" to each encoded string, preventing trivial decoding without knowledge of the junk removal algorithm. Each implant was given a "junk length" value when created, tracked by the controller software to allow seamless communication but prevent analysis of the command protocol on the wire. |
| T1012 Query Registry |
MalwareCHOPSTICK | CHOPSTICK provides access to the Windows Registry, which can be used to gather information. |
| T1027 Obfuscated Files or Information |
MalwareCORESHELL | CORESHELL obfuscates strings using a custom stream cipher. |
| T1027 Obfuscated Files or Information |
MalwareOLDBAIT | OLDBAIT obfuscates internal strings and unpacks them at startup. |
| T1027.011 Fileless Storage |
MalwareCHOPSTICK | CHOPSTICK may store RC4 encrypted configuration information in the Windows Registry. |
| T1027.016 Junk Code Insertion |
MalwareCORESHELL | CORESHELL contains unused machine instructions in a likely attempt to hinder analysis. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareOLDBAIT | OLDBAIT installs itself in |
| T1040 Network Sniffing |
GroupAPT28 | APT28 deployed the open source tool Responder to conduct NetBIOS Name Service poisoning, which captured usernames and hashed passwords that allowed access to legitimate credentials. APT28 close-access teams have used Wi-Fi pineapples to intercept Wi-Fi signals and user credentials. |
| T1071.001 Web Protocols |
MalwareCORESHELL | CORESHELL can communicate over HTTP for C2. |
| T1071.001 Web Protocols |
MalwareOLDBAIT | OLDBAIT can use HTTP for C2. |
| T1071.001 Web Protocols |
GroupAPT28 | Later implants used by APT28, such as CHOPSTICK, use a blend of HTTP, HTTPS, and other legitimate channels for C2, depending on module configuration. |
| T1071.003 Mail Protocols |
MalwareCORESHELL | CORESHELL can communicate over SMTP and POP3 for C2. |
| T1071.003 Mail Protocols |
GroupAPT28 | APT28 has used IMAP, POP3, and SMTP for a communication channel in various implants, including using self-registered Google Mail accounts and later compromised email servers of its victims. |
| T1071.003 Mail Protocols |
MalwareOLDBAIT | OLDBAIT can use SMTP for C2. |
| T1082 System Information Discovery |
MalwareCORESHELL | CORESHELL collects hostname and OS version data from the victim and sends the information to its C2 server. |
| T1090.002 External Proxy |
GroupAPT28 | APT28 used other victims as proxies to relay command traffic, for instance using a compromised Georgian military email server as a hop point to NATO victims. The group has also used a tool that acts as a proxy to allow C2 even if the victim is behind a router. APT28 has also used a machine to relay and obscure communications between CHOPSTICK and their server. |
| T1091 Replication Through Removable Media |
MalwareCHOPSTICK | Part of APT28's operation involved using CHOPSTICK modules to copy itself to air-gapped machines and using files written to USB sticks to transfer data and command traffic. |
| T1092 Communication Through Removable Media |
MalwareCHOPSTICK | Part of APT28's operation involved using CHOPSTICK modules to copy itself to air-gapped machines, using files written to USB sticks to transfer data and command traffic. |
| T1105 Ingress Tool Transfer |
MalwareCORESHELL | CORESHELL downloads another dropper from its C2 server. |
| T1112 Modify Registry |
MalwareCHOPSTICK | CHOPSTICK may modify Registry keys to store RC4 encrypted configuration information. |
| T1132.001 Standard Encoding |
MalwareCORESHELL | CORESHELL C2 messages are Base64-encoded. |
| T1210 Exploitation of Remote Services |
GroupAPT28 | APT28 exploited a Windows SMB Remote Code Execution Vulnerability to conduct lateral movement. |
| T1497 Virtualization/Sandbox Evasion |
MalwareCHOPSTICK | CHOPSTICK includes runtime checks to identify an analysis environment and prevent execution on it. |
| T1518.001 Security Software Discovery |
MalwareCHOPSTICK | CHOPSTICK checks for antivirus and forensics software. |
| T1555 Credentials from Password Stores |
MalwareOLDBAIT | OLDBAIT collects credentials from several email clients. |
| T1555.003 Credentials from Web Browsers |
MalwareOLDBAIT | OLDBAIT collects credentials from Internet Explorer, Mozilla Firefox, and Eudora. |
| T1573.001 Symmetric Cryptography |
MalwareCORESHELL | CORESHELL C2 messages are encrypted with custom stream ciphers using six-byte or eight-byte keys. |
| T1583.001 Domains |
GroupAPT28 | APT28 registered domains imitating NATO, OSCE security websites, Caucasus information resources, and other organizations. |
| T1680 Local Storage Discovery |
MalwareCORESHELL | CORESHELL collects the volume serial number from the victim and sends the information to its C2 server. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.