Cash, D. et al. (2020, December 14). Dark Halo Leverages SolarWinds Compromise to Breach Organizations. Retrieved December 29, 2020.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 extracted files from compromised networks. |
| T1036.004 Masquerade Task or Service |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 named tasks `\Microsoft\Windows\SoftwareProtectionPlatform\EventCacheManager` in order to appear legitimate. |
| T1036.005 Match Legitimate Resource Name or Location |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 renamed software and DLLs with legitimate names to appear benign. |
| T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 exfiltrated collected data over a simple HTTPS request to a password-protected archive staged on a victim's OWA servers. |
| T1053.005 Scheduled Task |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used `scheduler` and `schtasks` to create new tasks on remote host as part of their lateral movement. They manipulated scheduled tasks by updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration. APT29 also created a scheduled task to maintain SUNSPOT persistence when the host booted. |
| T1057 Process Discovery |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used multiple command-line utilities to enumerate running processes. |
| T1059.001 PowerShell |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used PowerShell to create new tasks on remote machines, identify configuration settings, exfiltrate data, and execute other commands. |
| T1059.003 Windows Command Shell |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used `cmd.exe` to execute commands on remote machines. |
| T1069 Permission Groups Discovery |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used the `Get-ManagementRoleAssignment` PowerShell cmdlet to enumerate Exchange management role assignments through an Exchange Management Shell. |
| T1070.008 Clear Mailbox Data |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 removed evidence of email export requests using `Remove-MailboxExportRequest`. |
| T1071.001 Web Protocols |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used HTTP for C2 and data exfiltration. |
| T1074.002 Remote Data Staging |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 staged data and files in password-protected archives on a victim's OWA server. |
| T1083 File and Directory Discovery |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 obtained information about the configured Exchange virtual directory using `Get-WebServicesVirtualDirectory`. |
| T1087 Account Discovery |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 obtained a list of users and their roles from an Exchange server using `Get-ManagementRoleAssignment`. |
| T1098.002 Additional Email Delegate Permissions |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 added their own devices as allowed IDs for active sync using `Set-CASMailbox`, allowing it to obtain copies of victim mailboxes. It also added additional permissions (such as Mail.Read and Mail.ReadWrite) to compromised Application or Service Principals. |
| T1098.005 Device Registration |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 registered devices in order to enable mailbox syncing via the `Set-CASMailbox` command. |
| T1114.002 Remote Email Collection |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 collected emails from specific individuals, such as executives and IT staff, using `New-MailboxExportRequest` followed by `Get-MailboxExportRequest`. |
| T1190 Exploit Public-Facing Application |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 exploited CVE-2020-0688 against the Microsoft Exchange Control Panel to regain access to a network. |
| T1482 Domain Trust Discovery |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used the `Get-AcceptedDomain` PowerShell cmdlet to enumerate accepted domains through an Exchange Management Shell. They also used AdFind to enumerate domains and to discover trust between federated domains. |
| T1550.004 Web Session Cookie |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used stolen cookies to access cloud resources and a forged `duo-sid` cookie to bypass MFA set on an email account. |
| T1560.001 Archive via Utility |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used 7-Zip to compress stolen emails into password-protected archives prior to exfltration; APT29 also compressed text files into zipped archives. |
| T1568 Dynamic Resolution |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used dynamic DNS resolution to construct and resolve to randomly-generated subdomains for C2. |
| T1606.001 Web Cookies |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 bypassed MFA set on OWA accounts by generating a cookie value from a previously stolen secret key. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.