Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, August 5). Threat Group-3390 Targets Organizations for Cyberespionage. Retrieved August 18, 2018.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupThreat Group-3390 | Threat Group-3390 actors have used a modified version of Mimikatz called Wrapikatz to dump credentials. They have also dumped credentials from domain controllers. |
| T1003.002 Security Account Manager |
GroupThreat Group-3390 | Threat Group-3390 actors have used gsecdump to dump credentials. They have also dumped credentials from domain controllers. |
| T1003.004 LSA Secrets |
GroupThreat Group-3390 | Threat Group-3390 actors have used gsecdump to dump credentials. They have also dumped credentials from domain controllers. |
| T1016 System Network Configuration Discovery |
GroupThreat Group-3390 | Threat Group-3390 actors use NBTscan to discover vulnerable systems. |
| T1027 Obfuscated Files or Information |
MalwareHTTPBrowser | HTTPBrowser's code may be obfuscated through structured exception handling and return-oriented programming. |
| T1030 Data Transfer Size Limits |
GroupThreat Group-3390 | Threat Group-3390 actors have split RAR files for exfiltration into parts. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareOwaAuth | OwaAuth uses the filename owaauth.dll, which is a legitimate file that normally resides in |
| T1046 Network Service Discovery |
GroupThreat Group-3390 | Threat Group-3390 actors use the Hunter tool to conduct network service discovery for vulnerable systems. |
| T1053.002 At |
GroupThreat Group-3390 | Threat Group-3390 actors use at to schedule tasks to run self-extracting RAR archives, which install HTTPBrowser or PlugX on other victims on a network. |
| T1056.001 Keylogging |
GroupThreat Group-3390 | Threat Group-3390 actors installed a credential logger on Microsoft Exchange servers. Threat Group-3390 also leveraged the reconnaissance framework, ScanBox, to capture keystrokes. |
| T1056.001 Keylogging |
MalwareOwaAuth | OwaAuth captures and DES-encrypts credentials before writing the username and password to a log file, |
| T1056.001 Keylogging |
MalwareHTTPBrowser | HTTPBrowser is capable of capturing keystrokes on victims. |
| T1059.003 Windows Command Shell |
MalwareHTTPBrowser | HTTPBrowser is capable of spawning a reverse shell on a victim. |
| T1059.003 Windows Command Shell |
MalwarePlugX | PlugX allows actors to spawn a reverse shell on a victim. |
| T1070.006 Timestomp |
MalwareOwaAuth | OwaAuth has a command to timestop a file or directory. |
| T1071.001 Web Protocols |
MalwarePlugX | PlugX can be configured to use HTTP for command and control. PlugX has also used HTTPS for C2. |
| T1071.001 Web Protocols |
MalwareOwaAuth | OwaAuth uses incoming HTTP requests with a username keyword and commands and handles them as instructions to perform actions. |
| T1071.001 Web Protocols |
MalwareHTTPBrowser | HTTPBrowser has used HTTP and HTTPS for command and control. |
| T1071.004 DNS |
MalwareHTTPBrowser | HTTPBrowser has used DNS for command and control. |
| T1071.004 DNS |
MalwarePlugX | PlugX can be configured to use DNS for command and control. |
| T1078 Valid Accounts |
GroupThreat Group-3390 | Threat Group-3390 actors obtain legitimate credentials using a variety of methods and use them to further lateral movement on victim networks. |
| T1083 File and Directory Discovery |
MalwareHTTPBrowser | HTTPBrowser is capable of listing files, folders, and drives on a victim. |
| T1083 File and Directory Discovery |
MalwareOwaAuth | OwaAuth has a command to list its directory and logical drives. |
| T1095 Non-Application Layer Protocol |
MalwarePlugX | PlugX can be configured to use raw TCP or UDP for command and control. |
| T1105 Ingress Tool Transfer |
GroupThreat Group-3390 | Threat Group-3390 has downloaded additional malware and tools, including through the use of `certutil`, onto a compromised host . |
| T1105 Ingress Tool Transfer |
MalwareHTTPBrowser | HTTPBrowser is capable of writing a file to the compromised system from the C2 server. |
| T1133 External Remote Services |
GroupThreat Group-3390 | Threat Group-3390 actors look for and use VPN profiles during an operation to access the network using external VPN services. Threat Group-3390 has also obtained OWA account credentials during intrusions that it subsequently used to attempt to regain access when evicted from a victim network. |
| T1189 Drive-by Compromise |
GroupThreat Group-3390 | Threat Group-3390 has extensively used strategic web compromises to target victims. |
| T1505.003 Web Shell |
MalwareOwaAuth | OwaAuth is a Web shell that appears to be exclusively used by Threat Group-3390. It is installed as an ISAPI filter on Exchange servers and shares characteristics with the China Chopper Web shell. |
| T1505.003 Web Shell |
MalwareASPXSpy | ASPXSpy is a Web shell. The ASPXTool version used by Threat Group-3390 has been deployed to accessible servers running Internet Information Services (IIS). |
| T1505.004 IIS Components |
MalwareOwaAuth | OwaAuth has been loaded onto Exchange servers and disguised as an ISAPI filter (owaauth.dll). The IIS w3wp.exe process then loads the malicious DLL. |
| T1560.003 Archive via Custom Method |
MalwareOwaAuth | OwaAuth DES-encrypts captured credentials using the key 12345678 before writing the credentials to a log file. |
| T1574.001 DLL |
GroupThreat Group-3390 | Threat Group-3390 has performed DLL search order hijacking to execute their payload. Threat Group-3390 has also used DLL side-loading, including by using legitimate Kaspersky antivirus variants as well as `rc.exe`, a legitimate Microsoft Resource Compiler. |
| T1574.001 DLL |
MalwarePlugX | PlugX has the ability to use DLL search order hijacking for installation on targeted systems. PlugX has also used DLL side-loading to evade anti-virus. PlugX has also used a legitimately signed executable to side-load a malicious payload within a DLL file. Cisco Talos MUSTANG PANDA PLUGX PUBLOAD MAY 2022Dell TG-3390EclecticIQ Mustang Panda PlugXEset PlugX Korplug Mustang Panda March 2022FireEye Clandestine Fox Part 2PWC Cloud Hopper Technical Annex April 2017Palo Alto PlugX June 2017Profero APT27 December 2020Proofpoint TA416 Europe March 2022Sophos Mustang Panda PLUGXSophos PlugX September 2022Stewart 2014Trend Micro DRBControl February 2020 |
| T1574.001 DLL |
MalwareHTTPBrowser | HTTPBrowser abuses the Windows DLL load order by using a legitimate Symantec anti-virus binary, VPDN_LU.exe, to load a malicious DLL that mimics a legitimate Symantec DLL, navlu.dll. HTTPBrowser has also used DLL side-loading. |
| T1588.002 Tool |
GroupThreat Group-3390 | Threat Group-3390 has obtained and used tools such as Impacket, pwdump, Mimikatz, gsecdump, NBTscan, and Windows Credential Editor. |
| T1608.002 Upload Tool |
GroupThreat Group-3390 | Threat Group-3390 has staged tools, including gsecdump and WCE, on previously compromised websites. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.