ATT&CKReferencesVolexity SolarWinds

Volexity SolarWinds

Cash, D. et al. (2020, December 14). Dark Halo Leverages SolarWinds Compromise to Breach Organizations. Retrieved December 29, 2020.

Open the source

Techniques2

Groups1

Software0

None recorded.

Campaigns1

Procedure examples23

TechniqueUsed byProcedure example
T1005
Data from Local System
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 extracted files from compromised networks.

T1036.004
Masquerade Task or Service
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 named tasks `\Microsoft\Windows\SoftwareProtectionPlatform\EventCacheManager` in order to appear legitimate.

T1036.005
Match Legitimate Resource Name or Location
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 renamed software and DLLs with legitimate names to appear benign.

T1048.002
Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 exfiltrated collected data over a simple HTTPS request to a password-protected archive staged on a victim's OWA servers.

T1053.005
Scheduled Task
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used `scheduler` and `schtasks` to create new tasks on remote host as part of their lateral movement. They manipulated scheduled tasks by updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration. APT29 also created a scheduled task to maintain SUNSPOT persistence when the host booted.

T1057
Process Discovery
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used multiple command-line utilities to enumerate running processes.

T1059.001
PowerShell
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used PowerShell to create new tasks on remote machines, identify configuration settings, exfiltrate data, and execute other commands.

T1059.003
Windows Command Shell
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used `cmd.exe` to execute commands on remote machines.

T1069
Permission Groups Discovery
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used the `Get-ManagementRoleAssignment` PowerShell cmdlet to enumerate Exchange management role assignments through an Exchange Management Shell.

T1070.008
Clear Mailbox Data
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 removed evidence of email export requests using `Remove-MailboxExportRequest`.

T1071.001
Web Protocols
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used HTTP for C2 and data exfiltration.

T1074.002
Remote Data Staging
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 staged data and files in password-protected archives on a victim's OWA server.

T1083
File and Directory Discovery
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 obtained information about the configured Exchange virtual directory using `Get-WebServicesVirtualDirectory`.

T1087
Account Discovery
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 obtained a list of users and their roles from an Exchange server using `Get-ManagementRoleAssignment`.

T1098.002
Additional Email Delegate Permissions
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 added their own devices as allowed IDs for active sync using `Set-CASMailbox`, allowing it to obtain copies of victim mailboxes. It also added additional permissions (such as Mail.Read and Mail.ReadWrite) to compromised Application or Service Principals.

T1098.005
Device Registration
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 registered devices in order to enable mailbox syncing via the `Set-CASMailbox` command.

T1114.002
Remote Email Collection
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 collected emails from specific individuals, such as executives and IT staff, using `New-MailboxExportRequest` followed by `Get-MailboxExportRequest`.

T1190
Exploit Public-Facing Application
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 exploited CVE-2020-0688 against the Microsoft Exchange Control Panel to regain access to a network.

T1482
Domain Trust Discovery
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used the `Get-AcceptedDomain` PowerShell cmdlet to enumerate accepted domains through an Exchange Management Shell. They also used AdFind to enumerate domains and to discover trust between federated domains.

T1550.004
Web Session Cookie
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used stolen cookies to access cloud resources and a forged `duo-sid` cookie to bypass MFA set on an email account.

T1560.001
Archive via Utility
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used 7-Zip to compress stolen emails into password-protected archives prior to exfltration; APT29 also compressed text files into zipped archives.

T1568
Dynamic Resolution
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used dynamic DNS resolution to construct and resolve to randomly-generated subdomains for C2.

T1606.001
Web Cookies
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 bypassed MFA set on OWA accounts by generating a cookie value from a previously stolen secret key.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.