ATT&CKReferencesCybereason Cobalt Kitty 2017

Cybereason Cobalt Kitty 2017

Dahan, A. (2017). Operation Cobalt Kitty. Retrieved December 27, 2018.

Open the source

Techniques1

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples76

TechniqueUsed byProcedure example
T1003
OS Credential Dumping
GroupAPT32

APT32 used GetPassword_x64 to harvest credentials.

T1003.001
LSASS Memory
GroupAPT32

APT32 used Mimikatz and customized versions of Windows Credential Dumper to harvest credentials.

T1005
Data from Local System
MalwareGoopy

Goopy has the ability to exfiltrate documents from infected systems.

T1012
Query Registry
MalwareDenis

Denis queries the Registry for keys and values.

T1016
System Network Configuration Discovery
MalwareDenis

Denis uses ipconfig to gather the IP address from the system.

T1016
System Network Configuration Discovery
GroupAPT32

APT32 used the ipconfig /all command to gather the IP address from the system.

T1018
Remote System Discovery
GroupAPT32

APT32 has enumerated DC servers using the command net group "Domain Controllers" /domain. The group has also used the ping command.

T1021.002
SMB/Windows Admin Shares
GroupAPT32

APT32 used Net to use Windows' hidden network shares to copy their tools to remote machines for execution.

T1027
Obfuscated Files or Information
MalwareDenis

Denis obfuscates its code and encrypts the API names.

T1027.001
Binary Padding
MalwareGoopy

Goopy has had null characters padded in its malicious DLL payload.

T1027.010
Command Obfuscation
MalwareDenis

Denis has encoded its PowerShell commands in Base64.

T1027.010
Command Obfuscation
GroupAPT32

APT32 has used the `Invoke-Obfuscation` framework to obfuscate their PowerShell.

T1027.013
Encrypted/Encoded File
GroupAPT32

APT32 has performed code obfuscation, including encoding payloads using Base64 and using a framework called "Dont-Kill-My-Cat (DKMC). APT32 also encrypts the library used for network exfiltration with AES-256 in CBC mode in their macOS backdoor.

T1027.016
Junk Code Insertion
MalwareGoopy

Goopy's decrypter have been inflated with junk code in between legitimate API functions, and also included infinite loops to avoid analysis.

T1033
System Owner/User Discovery
MalwareDenis

Denis enumerates and collects the username from the victim’s machine.

T1033
System Owner/User Discovery
GroupAPT32

APT32 collected the victim's username and executed the whoami command on the victim's machine. APT32 executed shellcode to collect the username on the victim's machine.

T1033
System Owner/User Discovery
MalwareGoopy

Goopy has the ability to enumerate the infected system's user name.

T1036
Masquerading
GroupAPT32

APT32 has disguised a Cobalt Strike beacon as a Flash Installer.

T1036.005
Match Legitimate Resource Name or Location
MalwareGoopy

Goopy has impersonated the legitimate goopdate.dll, which was dropped on the target system with a legitimate GoogleUpdate.exe.

T1036.005
Match Legitimate Resource Name or Location
GroupAPT32

APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update. APT32 has also renamed a Cobalt Strike beacon payload to install_flashplayers.exe.

T1041
Exfiltration Over C2 Channel
MalwareGoopy

Goopy has the ability to exfiltrate data over the Microsoft Outlook C2 channel.

T1046
Network Service Discovery
GroupAPT32

APT32 performed network scanning on the network to search for open ports, services, OS finger-printing, and other vulnerabilities.

T1047
Windows Management Instrumentation
GroupAPT32

APT32 used WMI to deploy their tools on remote machines and to gather information about the Outlook process.

T1049
System Network Connections Discovery
GroupAPT32

APT32 used the netstat -anpo tcp command to display TCP connections on the victim's machine.

T1053.005
Scheduled Task
MalwareGoopy

Goopy has the ability to maintain persistence by creating scheduled tasks set to run every hour.

T1053.005
Scheduled Task
GroupAPT32

APT32 has used scheduled tasks to persist on victim systems.

T1055
Process Injection
GroupAPT32

APT32 malware has injected a Cobalt Strike beacon into Rundll32.exe.

T1055.012
Process Hollowing
MalwareDenis

Denis performed process hollowing through the API calls CreateRemoteThread, ResumeThread, and Wow64SetThreadContext.

T1056.001
Keylogging
GroupAPT32

APT32 has abused the PasswordChangeNotify to monitor for and capture account password changes.

T1057
Process Discovery
MalwareGoopy

Goopy has checked for the Google Updater process to ensure Goopy was loaded properly.

T1059
Command and Scripting Interpreter
GroupAPT32

APT32 has used COM scriptlets to download Cobalt Strike beacons.

T1059.001
PowerShell
MalwareDenis

Denis has a version written in PowerShell.

T1059.001
PowerShell
GroupAPT32

APT32 has used PowerShell-based tools, PowerShell one-liners, and shellcode loaders for execution.

T1059.003
Windows Command Shell
MalwareDenis

Denis can launch a remote shell to execute arbitrary commands on the victim’s machine.

T1059.003
Windows Command Shell
GroupAPT32

APT32 has used cmd.exe for execution.

T1059.003
Windows Command Shell
MalwareGoopy

Goopy has the ability to use cmd.exe to execute commands passed from an Outlook C2 channel.

T1059.005
Visual Basic
GroupAPT32

APT32 has used macros, COM scriptlets, and VBS scripts.

T1059.005
Visual Basic
MalwareGoopy

Goopy has the ability to use a Microsoft Outlook backdoor macro to communicate with its C2.

T1059.007
JavaScript
GroupAPT32

APT32 has used JavaScript for drive-by downloads and C2 communications.

T1070.004
File Deletion
MalwareDenis

Denis has a command to delete files from the victim’s machine.

T1070.008
Clear Mailbox Data
MalwareGoopy

Goopy has the ability to delete emails used for C2 once the content has been copied.

T1071.001
Web Protocols
GroupAPT32

APT32 has used JavaScript that communicates over HTTP or HTTPS to attacker controlled domains to download additional frameworks. The group has also used downloaded encrypted payloads over HTTP.

T1071.001
Web Protocols
MalwareGoopy

Goopy has the ability to communicate with its C2 over HTTP.

T1071.003
Mail Protocols
GroupAPT32

APT32 has used email for C2 via an Office macro.

T1071.003
Mail Protocols
MalwareGoopy

Goopy has the ability to use a Microsoft Outlook backdoor macro to communicate with its C2.

T1071.004
DNS
MalwareDenis

Denis has used DNS tunneling for C2 communications.

T1071.004
DNS
MalwareGoopy

Goopy has the ability to communicate with its C2 over DNS.

T1082
System Information Discovery
MalwareDenis

Denis collects OS information and the computer name from the victim’s machine.

T1083
File and Directory Discovery
MalwareDenis

Denis has several commands to search directories for files.

T1087.001
Local Account
GroupAPT32

APT32 enumerated administrative users using the commands net localgroup administrators.

Showing the first 50.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.